CVE-2025-14929:Transformers脚本因未校验.pth文件致任意代码执行
CVE-2025-14929 的核心漏洞点在于 Transformers 相关脚本中使用 torch.load() 加载外部不可信 .pth 文件时,未进行任何安全校验,且默认启用 pickle 反序列化机制。
Radware has unveiled the launch of its Radware API Security Service, an end-to-end solution designed to protect APIs throughout their entire lifecycle using real-time production traffic. Radware API Security Service offers APIs advanced protection against the OWASP Top 10 API Security Risks, including sophisticated Layer 7 DDoS attacks. APIs power most modern applications, but they also create major security blind spots. API security tools often generate large numbers of theoretical alerts without showing risk, making … More →
The post Radware targets API blind spots with real-time lifecycle protection appeared first on Help Net Security.