Urgent.News

What's breaking now, across thousands of outlets.

Tech

Your container images are unsigned. In the AI era, that’s a ticking time bomb.

Most organizations that know they should sign their images still don’t. Not because they disagree, but because the path to The post Your container images are unsigned. In the AI era, that’s a ticking time bomb. appeared first on The New Stack .

Your container images are unsigned. In the AI era, that’s a ticking time bomb.

Most organizations have not yet adopted image signing, not because they disagree with the practice, but due to the complexity of implementing it effectively. As a result, delivery pipelines rely on unverifiable trust, leaving them vulnerable to attack at any stage. Malicious images can masquerade as legitimate packages, waiting to be pulled by a team.

Compromised CI/CD pipelines can silently inject tampered artifacts into production builds without any cryptographic evidence of modification. Stolen credentials can allow a malicious actor to impersonate a trusted publisher. Within a single organization, inconsistent practices mean some teams sign their images while others skip that step, creating gaps in the chain of trust that nobody has mapped.

Base image inheritance further complicates the issue, as every container image inherits the security posture of its parent. This means that one compromised base image can propagate across dozens of downstream services before any issues become apparent. Scanning is reactive and can only identify vulnerabilities within an image, not whether the image has been tampered with since it left the build system.

Cryptographic signing, on the other hand, provides proactive provenance, offering a solution that answers the more crucial question: "who built this, and has it been modified since it left the build system?" As workloads change faster than tooling, the AI era has increased the urgency of this issue. Model weights, training datasets, inference runtimes, and agent tooling are increasingly shipped as OCI artifacts, many of which lack vulnerability databases or CVEs for matching.

The absence of these databases makes it challenging to assess the security of these artifacts. A recent example from February 2024 involves malicious PyTorch models on Hugging Face that opened a reverse shell when loaded, exploiting pickle's __reduce__ hook to execute arbitrary code. Despite the discovery of roughly 100 models carrying malicious payloads, there were no vulnerabilities identified since there was nothing for a CVE to describe.

The threat resided in the serialized weights. To address this, model-specific scanning has been implemented on Hugging Face, which runs ClamAV plus a pickle import scan on every file pushed to the Hub. However, these scanning methods are already being evaded. In February 2025, ReversingLabs revealed nullifAI, two models that bypassed picklescan by compressing with 7z instead of ZIP and by corrupting the pickle stream after the payload ran, causing static analysis to error out on a file whose reverse shell had already executed.

Hugging Face promptly removed the models and patched picklescan. This illustrates the ongoing challenge of securing AI model artifacts. Signing is not a simple checkbox; it requires consistent implementation across all teams and pipelines without causing any slowdown. The registry is the most suitable layer for implementing image signing, as it already holds identity context, enforces access policies, and stores metadata describing the contents of an image.

By making signing invisible to users, the registry can make this crucial security measure more manageable.

Written by urgent.news from The New Stack's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at thenewstack.io →

More in Tech

More from Friday 14 August →