September 8, 2026
- Nightmare Eclipse dropped PoC exploits for CrowdStrike, Nvidia and Avast products, each yielding privilege escalation to a SYSTEM shell (SecurityWeek).
· New Tools & Releases
in N-able Ships a Fourth N-central Hotfix in Five Weeks — and Can't Agree Whether It's Exploited
September 5, 2026
- Nvidia is acquiring Hugging Face for ~$12.9B, putting the default distribution point for open weights — 18 million developers, 200,000 companies — under a single hardware vendor (The Decoder, SecurityWeek). Huang promises the hub stays open and hardware-neutral; for model supply-chain purposes it is now one company's origin.
· Agentic AI & Model Security
in 18,000 Posts on a Dead German Wiki: OpenAI's Agents Were Trading Sandbox Escapes in May
September 2, 2026
- CrowdStrike and NVIDIA built a paired attacker/defender model set and ran them against each other on a digital twin of NVIDIA's own infrastructure; both run on Nemotron, trained on Falcon telemetry and 15 years of IR data (@IntCyberDigest).
· AI & Model Security
in OpenAI Says Astra Crossed the Line: Autonomous Zero-Day Discovery at "Critical" Cyber Risk
August 26, 2026
- An exposed Ollama API creates a model-poisoning path in NVIDIA’s NemoClaw/OpenClaw stack. In affected configurations, a malicious webpage could reach the unauthenticated local model service and persistently corrupt agent behavior. The Hacker News and Dark Reading cover the networking failure.
· AI & Model Security
- OpenAI’s first in-house inference chip, Jalapeño, posted strong early benchmarks. OpenAI published initial results, and The Decoder cites SemiAnalysis tests placing it ahead of NVIDIA Blackwell and Rubin on selected throughput and energy-efficiency workloads. Broad independent validation is still needed.
· AI & Model Security
in Oracle WebLogic Is Under Active Attack
August 14, 2026
- The LiteLLM compromise is far larger than initially reported. New reporting from CloudSEK and Hudson Rock puts the blast radius at ~2,500 organizations — including Nvidia, AWS, and Samsung Electronics — with terabytes of credentials exfiltrated in a ~40-minute window and 434,000 CI/CD pipelines exposed (earlier coverage). Some commenters flagged it as possibly the largest credential compromise on record. (Ars Technica, discussion)
· Supply Chain
in vCenter Under Active Exploitation: Critical RCE Weaponized for Reverse-SSH Persistence Across 47 Countries
July 28, 2026
- NVIDIA and 37 members (including CrowdStrike, IBM, Palantir, Microsoft and Hugging Face) launched the Open Secure AI Alliance and open-sourced its NOOA framework, aimed at giving defenders open tooling to test, audit and protect models and agents (The Hacker News, SecurityWeek).
· AI & Model Security
in Agentic AI Muscles Into the Offensive Toolkit
June 27, 2026
Amazon Q Developer suffered a critical vulnerability (CVE-2026-12957, CVSS 8.5) allowing malicious Git repositories to execute arbitrary code and steal cloud credentials through untrusted MCP configurations. The US government has begun individually approving access to frontier AI models, with OpenAI's GPT-5.6 requiring customer-by-customer authorization and Anthropic's Claude Mythos 5 restricted to select critical-infrastructure organizations. NVIDIA Triton Inference Server had a critical auth-bypass vulnerability (CVE-2026-24207, CVSS 9.8) with public exploits enabling pre-auth RCE. The Miasma supply-chain campaign compromised npm packages and GitHub Actions workflows to harvest developer credentials across the Go ecosystem.