started · updated
Replicate discloses infrastructure vulnerability addressed via Wiz report
Replicate has disclosed a security vulnerability in its infrastructure that could have allowed a malicious machine learning model to access sensitive data. The flaw was originally identified and reported by the cloud security company Wiz in January 2024.
Replicate reported that it deployed a full mitigation within 24 hours of discussing the issue with Wiz. Following the initial fix, the company implemented additional security measures, including the encryption of all internal traffic and the restriction of privileged network access for all model containers. During the investigation, Replicate found no evidence that the vulnerability had been exploited.