m00dy.sh/Tag
supply-chain
5 posts tagged supply-chain.
Jul 29, 2026
Structure-Aware Fuzzing for ML Model Parsers
Loading a model from a hub means running a binary parser on a file a stranger gave you. This is the map for Crucible: what the attack surface is, why a format-aware fuzzer beats a dumb one on it, and how a seed file becomes a filed advisory.
Jun 13, 2026
Found by AI, Fixed by AI
A structure-aware fuzzer found a small ONNX memory-safety bug, GitHub Copilot helped patch it upstream, and the public issue-to-merge loop closed the same afternoon.
May 15, 2026
The Format That Got It Right
SafeTensors did not survive fuzzing by luck. It survived because the format puts validation before allocation, keeps code out of the file, and treats model loading as an input-parsing problem.
May 11, 2026
Signing Is Not Sealing
Post-quantum signatures are entering supply-chain infrastructure. Any ML artifact signing profile that adopts ML-DSA should get one deployment detail right before it ships: randomized mode opens a 256-bit hidden command channel that no deployed verifier can inspect.
May 01, 2026
Channel, Decoder, Substrate: A Vocabulary for ML Attacks
An ML attack is the composition of three things: a channel that carries information, a decoder that reads the channel, and a substrate that runs the decoder. Naming the shape changes how you think about both offense and defense.