daily cyber × ai intelligence

index

tagged

[nvidia]

7 editions · 7 items

August 26, 2026

  • An exposed Ollama API creates a model-poisoning path in NVIDIA’s NemoClaw/OpenClaw stack. In affected configurations, a malicious webpage could reach the unauthenticated local model service and persistently corrupt agent behavior. The Hacker News and Dark Reading cover the networking failure. · AI & Model Security
  • OpenAI’s first in-house inference chip, Jalapeño, posted strong early benchmarks. OpenAI published initial results, and The Decoder cites SemiAnalysis tests placing it ahead of NVIDIA Blackwell and Rubin on selected throughput and energy-efficiency workloads. Broad independent validation is still needed. · AI & Model Security

in Oracle WebLogic Is Under Active Attack

August 14, 2026

  • The LiteLLM compromise is far larger than initially reported. New reporting from CloudSEK and Hudson Rock puts the blast radius at ~2,500 organizations — including Nvidia, AWS, and Samsung Electronics — with terabytes of credentials exfiltrated in a ~40-minute window and 434,000 CI/CD pipelines exposed (earlier coverage). Some commenters flagged it as possibly the largest credential compromise on record. (Ars Technica, discussion) · Supply Chain

in vCenter Under Active Exploitation: Critical RCE Weaponized for Reverse-SSH Persistence Across 47 Countries

June 27, 2026

Amazon Q Coding Assistant Hijacked Through Malicious MCP Configs as Washington Starts Gating Frontier Models Customer-by-Customer

Amazon Q Developer suffered a critical vulnerability (CVE-2026-12957, CVSS 8.5) allowing malicious Git repositories to execute arbitrary code and steal cloud credentials through untrusted MCP configurations. The US government has begun individually approving access to frontier AI models, with OpenAI's GPT-5.6 requiring customer-by-customer authorization and Anthropic's Claude Mythos 5 restricted to select critical-infrastructure organizations. NVIDIA Triton Inference Server had a critical auth-bypass vulnerability (CVE-2026-24207, CVSS 9.8) with public exploits enabling pre-auth RCE. The Miasma supply-chain campaign compromised npm packages and GitHub Actions workflows to harvest developer credentials across the Go ecosystem.