Safetensors Won. Model Serialization Attacks Didn’t Stop.
Safetensors became the default model format, yet serialization attacks moved into conversion pipelines, loaders, and unsafe infrastructure.
Read the issueFree newsletter from the Awesome MLSecOps maintainer
Mapping the AI security landscape: weekly insights on AI governance, GenAI threat modeling, and deep dives on MLSecOps best practices, tooling, and attack vectors for CISOs, security professionals, and AI engineers.
Delivered by email. Every issue stays free to read in the archive below and on the newsletter site.
What subscribers get
Model serialization exploits, prompt injection chains, agent abuse, and MLOps infrastructure compromises explained with primary sources.
What the scanners, guardrails, and red-team frameworks in this catalog actually catch, and where they fall short.
New Awesome MLSecOps entries and category changes, so you do not have to watch the repository.
Written for CISOs, security engineers, and AI engineers by the maintainer of this catalog. No vendor placements.
Dated archive
Each entry summarizes an original issue and links to the canonical post on The MLSecOps Hacker.
Safetensors became the default model format, yet serialization attacks moved into conversion pipelines, loaders, and unsafe infrastructure.
Read the issueA practical review of model serialization risks, machine learning supply-chain vulnerabilities, and defensive practices for handling model artifacts safely.
Read the issueAn introduction to the discipline of securing machine learning systems and the teams, controls, and operating practices that support it.
Read the issue