Search
Find merged stories by title or summary.
NVIDIA security advisory (AV26-957)
Serial number: AV26-957 Date: September 23, 2026 As of September 22, 2026, NVIDIA is affected by vulnerabilities in the following products: • Infrastructure Controller • Versions 0 to 1.9 • NeMo Speech • Versions 0.0 to 2.9 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. • Security Bulletin: NVIDIA Infrastructure Controller - September 2026 • Security Bulletin: NVIDIA NeMo Speech - September 2026 • NVIDIA Product Security NVIDIA security advisory (AV26-957) - Canadian Centre for Cyber Security
Security updates for Wednesday
Security updates have been issued by AlmaLinux (coreutils, postgresql18-postgis, and postgresql:16), Debian (memcached), Fedora (chromium, cyrus-imapd, dotnet10. 0, dotnet8. 0, dotnet9. 0, freeipmi, kernel, libxmp, perl-Net-DNS, and postgresql16-anonymizer), Mageia (cpio, diffutils, perl-Dancer2, and rest), Oracle (389-ds-base and firefox), Red Hat (opentelemetry-collector and osbuild-composer), SUSE (amazon-cloudwatch-agent, amazon-ssm-agent, apko, apptainer, bazel-rules-python-source, bind, cups, firefox, freeipmi, gdb, google-osconfig-agent, kernel, kyverno, libipa_hbac-devel, libsoup, libsoup-3_0-0, libtpms, openssl-certs, perl-Authen-SASL, php-composer2, python313-PyMuPDF, thunderbird, and util-linux), and Ubuntu (gzip, linux-aws, linux-aws-5. 15, linux-aws-fips, linux-nvidia-tegra-igx, linux-azure, linux-oracle, linux-azure-7. 0, linux-azure-fde-6.
NVIDIA Infrastructure Controller Hit by 14 Security Flaws Enabling Privilege Escalation and Code Execution
NVIDIA has released version 2.0 of its Infrastructure Controller to remediate 14 security vulnerabilities in the Linux-based infrastructure-management software, including a critical hard-coded credentials flaw that could enable remote compromise. The vulnerabilities affect versions 0 through 1.9, and NVIDIA is urging users to upgrade or clone the latest release from the project’s GitHub repository. NVIDIA’s security bulletin, issued on September 22, 2026, rates the flaws from medium to critical severity under CVSS v3.1. NVIDIA Infrastructure Controller Hit by 14 Security Flaws Collectively, the weaknesses could expose affected deployments to code execution, privilege escalation, data tampering, denial-of-service conditions , and information disclosure. The highest-rated issue, CVE-2026-65113, carries a CVSS score of 9. 8.
Lapsus$ Explained | The Hacking Group Behind Okta, Uber, Nvidia and Its Return
Lapsus$ is a hacking and extortion group first known for breaching Okta, Microsoft, Nvidia, Samsung, and Uber in 2021 and 2022 using social engineering rather than malware, and it has since reemerged as part of a larger collective called Scattered Lapsus$ Hunters. Unlike ransomware gangs that rely on encryption, Lapsus$ built its reputation on stealing source code and internal data, then threatening to leak it publicly unless the victim paid or complied with its demands. This tactic made it one of the most disruptive threat actors of the past few years despite reportedly being run largely by teenagers. That threat hasn’t gone away; it’s evolved.
NVIDIA Fixes Linux Component Flaws That Could Expose Sensitive System Information
NVIDIA released a security update for its Infrastructure Controller software for Linux, addressing 14 vulnerabilities that could let attackers access sensitive system information, execute code, alter data, or disrupt affected environments. The update, published in NVIDIA’s September 2026 Infrastructure Controller security bulletin, affects versions 0 through 1. 9. NVIDIA recommends that organizations clone or update the software to version 2. 0 or later to address all reported issues. Among the patched flaws is CVE-2026-65127, a medium-severity vulnerability caused by uncleared debug information. The issue carries a CVSS score of 4. 1 and is tracked as CWE-1258. An attacker with local access, high privileges, and favorable conditions could potentially retrieve sensitive system information left exposed through debugging artifacts.
Open-Source NVIDIA "Nouveau" Driver Sees Patches For HDMI Deep Color Support
The Nouveau Linux kernel graphics driver for open-source NVIDIA driver support has new patches posted for enabling HDMI Deep Color support...
ZLUDA Now Implements Some NVIDIA cuFFT APIs With hipFFT
ZLUDA as the open-source project working on CUDA for non-NVIDIA GPUs like AMD Radeon graphics cards now has implemented support for some of NVIDIA's core cuFFT APIs...
Nvidia CEO rejects AI apocalypse warnings, claims they're overblown - Cybernews
Nvidia CEO rejects AI apocalypse warnings, claims they're overblown Cybernews
Nvidia rejects RTX 5090 graphics card warranty claim over faded serial number - Cybernews
Nvidia rejects RTX 5090 graphics card warranty claim over faded serial number Cybernews
Security updates for Friday
Security updates have been issued by AlmaLinux (apr-util and qt6-qt5compat), Debian (libevent and ruby-rack), Fedora (bluez, corosync, curl, dokuwiki, grpcurl, libevent, and rest), Oracle (gstreamer1-plugins-bad-free, perl-DBI, python-urllib3, qt5-qtbase, qt6-qt5compat, and thunderbird), Red Hat (osbuild-composer), SUSE (azure-storage-azcopy, chromedriver, corosync, ggml-devel, helm, kernel, libmariadb-devel, libzypp, zypper, opensc, php7, tomcat10, and waylyrics), and Ubuntu (apache2, beets, glibc, kissfft, libebml, linux-nvidia-6. 17, php8. 1, php8. 3, php8. 5, and python2. 7, python3. 4, python3. 5, python3. 6, python3. 7, python3. 8, python3. 9, python3. 10, python3. 11, python3. 12, python3. 14).
NVIDIA NVK Driver Lands Improvement To Help With Valve's Gamescope
Merged today for next quarter's Mesa 26. 3 release is an improvement for the open-source NVIDIA "NVK" Vulkan driver paired with the Nouveau kernel driver. This latest NVK improvement benefits usage of Valve's Gamescope micro-compositor and should help with performance during game recording and remote play...
Experimental Patches Get Nouveau+NVK Working On NVIDIA DGX Spark GB10
Red Hat's David Airlie has managed another open-source graphics engineering feat... Getting the Nouveau reverse-engineered kernel graphics driver and Mesa NVK Vulkan driver running on the GB10 Grace Blackwell Superchip with the DGX Spark system...
DLSS5VKLayer Wires Up NVIDIA DLSS 5 For Native Linux Games & Steam Play
An interesting new open-source project for those looking to make use of NVIDIA DLSS 5 on Linux is DLSS5VKLayer. The DLSS5VKLayer is a Linux Vulkan layer that works for both native Linux games as well as Steam Play (Proton) Windows games for experimental DLSS 5 support...
Chaotic Eclipse Released A PoC For NVIDIA GreenSection Memory Corruption Zero-Day
Chaotic Eclipse released GreenSection, a PoC exploit for an Nvidia GreenSection Memory Corruption Zero-Day Security researcher Chaotic Eclipse , also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting Nvidia. The researcher named the exploit GreenSection, it triggers a Memory Corruption flaw. The researcher disclosed a potential security vulnerability in NVIDIA’s Windows user-mode components. Several NVIDIA components share a global memory section that gives all users full read/write access. Although the software performs checks to prevent misuse, it reuses data from this shared memory at runtime, which can lead to an out-of-bounds memory write.
Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits
The proof-of-concept (PoC) exploits lead to privilege escalation, spawning a shell with System privileges. The post Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits appeared first on SecurityWeek .
Nouveau Preparations For HDMI 2.1 DSC, AMD HDMI FreeSync Fixes For Linux 7.4
Last week's set of DRM-Misc-Next changes submitted to DRM-Next with targeting the upcoming Linux 7. 4 kernel cycle features HDMI 2. 1 related work for both the AMDGPU kernel driver as well as the Nouveau open-source NVIDIA driver...
CrowdStrike Launches SafeMind Frontier Cybersecurity Models Built With NVIDIA Nemotron
CrowdStrike has launched SafeMind, a family of purpose-built cybersecurity models and agentic AI harnesses designed to help defenders identify, validate, and remediate threats inside the Falcon platform. Announced during Fal.Con 2026 in Las Vegas, SafeMind represents CrowdStrike’s move away from relying solely on general-purpose frontier models for security operations. The company said the new system was created specifically for cyber defense, combining offensive simulation, defensive response, and continuous model improvement within a closed-loop architecture. CrowdStrike Launches SafeMind Frontier Cybersecurity Models Developed by CrowdStrike’s newly created Cyber Superintelligence Lab, SafeMind is an agentic system that acts on security findings rather than simply producing alerts, summaries, or recommendations.
NVIDIA Posts vGPU Manager & VFIO Variant Driver For Open-Source Nova
NVIDIA continues building out more functionality around the open-source, upstream Nova kernel graphics driver within the Linux kernel. Making it out to the mailing list this Saturday is a set of 13 patches for introducing a NVIDIA vGPU manager and VFIO variant driver...
Nouveau Lands Display Fixes For NVIDIA Blackwell GPUs As It Works Toward HDMI 2.1
This week's Direct Rendering Manager (DRM) fixes that were merged ahead of Sunday's Linux 7.3-rc2 release contain a number of fixes to the open-source Nouveau driver's display support for current-generation NVIDIA Blackwell GPUs...
Nvidia’s $12.9B Hugging Face deal could benefit enterprises
The chipmaker’s acquisition could eventually bring additional security resources and model evaluation tools to the platform, according to experts.
Nvidia Is Buying AI Platform Hugging Face for $13 Billion
The deal highlights Nvidia’s push to champion increasingly popular open-source AI models. The post Nvidia Is Buying AI Platform Hugging Face for $13 Billion appeared first on SecurityWeek .
Capsule Security Launches ‘AI Circuit Breaker’ to Stop Rogue Agents
New models, trained using NVIDIA Nemotron 3 Ultra, aim to catch rogue agent behavior before it executes, without the latency of large-model review. The post Capsule Security Launches ‘AI Circuit Breaker’ to Stop Rogue Agents appeared first on SecurityWeek .
NVIDIA-Started Open Secure AI Alliance Moves To The Linux Foundation
Earlier this year NVIDIA led an effort with more than two dozen other companies to launch the Open Secure AI Alliance with a focus on keeping open-source AI models secure. The Open Secure AI Alliance today is transitioning from being stewarded by NVIDIA to becoming a Linux Foundation project...
Is your monitor flickering, too? Users report bug in Nvidia's new GPU driver - Cybernews
Is your monitor flickering, too? Users report bug in Nvidia's new GPU driver Cybernews
GPUThor hardware attack can root Nvidia GPU systems
Hardware security researchers from University of Toronto have developed a new memory bit flipping technique that significantly improves on previously known attacks against GPU memory. The new method can defeat the error-correcting codes (ECC) defense used on enterprise Nvidia GPUs and can lead to root access on the underlying system. Dubbed GPUThor, the technique falls in a category of attacks known as Rowhammer that exploits the cell density of modern random access memory (RAM) chips. The original Rowhammer attack was demonstrated against DDR3 and DDR4 chips back in 2015 and relies on an older observation that tightly packed rows of memory cells can sometimes leak electrical charges to adjacent rows, flipping the stored bit values in those cells from 0 to 1 or the other way around.
Hackers can overwhelm Nvidia GPU ECC protections with GPUThor exploit and gain root access - Cybernews
Hackers can overwhelm Nvidia GPU ECC protections with GPUThor exploit and gain root access Cybernews
NVIDIA NemoClaw flaw can hijack AI agents online - Cybernews
NVIDIA NemoClaw flaw can hijack AI agents online Cybernews
New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access
Academic researchers have disclosed a Rowhammer attack impacting NVIDIA workstation GPUs with GDDR6 memory that defeats error correction codes (ECC), the mitigation NVIDIA recommends against GPU Rowhammer, and enables denial-of-service (DoS) and privilege escalation to a root shell. Dubbed GPUThor, the attack was developed by researchers at the University of Toronto, who hammered four DRAM
Nvidia’s breach might help cybercriminals run malware campaigns - TechRepublic
Nvidia’s breach might help cybercriminals run malware campaigns TechRepublic
New GPUThor attack defeats NVIDIA ECC protection for root access
A newly disclosed Rowhammer attack called GPUThor can bypass error-correcting code (ECC) protections on NVIDIA GPUs, enabling denial-of-service (DoS) and root-level privilege escalation. [... ]
Adobe and Nvidia Patch Dozens of Vulnerabilities
Adobe and Nvidia each published several advisories, including ones that address critical vulnerabilities in their products. The post Adobe and Nvidia Patch Dozens of Vulnerabilities appeared first on SecurityWeek .
NemoClaw’s AI can be poisoned through a browser tab
A vulnerability affecting Nvidia’s NemoClaw could let an attacker gain control of the local Ollama model server through a single malicious website visit on the victim’s machine. According to a Cyera research, the flaw could give attackers unauthenticated access to the server, allowing them to plant instructions into the model that persist across future conversations. The attacker doesn’t directly connect to the victim’s Ollama server from the internet. Instead, the malicious webpage tricks the browser into reaching the locally running Ollama API through DNS rebinding. Once that happens, the model’s chat template, a layer that controls how messages are presented to the model, is manipulated to add malicious instructions to the agent’s system prompts.
GPUThor Rowhammer attack beats ECC on NVIDIA workstation GPUs
University of Toronto researchers have developed a new Rowhammer technique named GPUThor that can overwhelm error-correcting memory on several NVIDIA workstation GPUs, enabling crashes and even privilege escalation to root. The attack produces up to 23,500 times more bit flips than the first GPU Rowhammer attack, bringing GPU attack rates close to those seen on … The post GPUThor Rowhammer attack beats ECC on NVIDIA workstation GPUs appeared first on CyberInsider .
CVE-2026-65105 - NVIDIA NemoClaw Inference Server Authentication Bypass
CVE ID : CVE-2026-65105 Published : Aug. 25, 2026, 8:15 p. m. • 57 minutes ago Description : NVIDIA NemoClaw for Linux contains a vulnerability in its inference server setup, where a remote attacker may access the inference service without authentication. A successful exploit of this vulnerability may lead to information disclosure and denial of service. Severity: 8.1 • HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-65088 - NVIDIA NemoClaw Sensitive Information Disclosure
CVE ID : CVE-2026-65088 Published : Aug. 25, 2026, 8:15 p. m. • 57 minutes ago Description : NVIDIA NemoClaw contains a vulnerability where an attacker could cause invocation of process using visible sensitive information. A successful exploit of this vulnerability might lead to information disclosure. Severity: 5.5 • MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE-2026-65087 - NVIDIA NemoClaw Credential Improper Authorization Vulnerability
CVE ID : CVE-2026-65087 Published : Aug. 25, 2026, 8:15 p. m. • 57 minutes ago Description : NVIDIA NemoClaw contains a vulnerability where an attacker could cause insufficiently protected credentials . A successful exploit of this vulnerability might lead to information disclosure and data tampering. Severity: 5.6 • MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Finding Nemo(Claw): Networking Issue Allows for LLM Poisoning in OpenClaw
Attackers can exploit a security bug in NVIDIA's tool to gain unauthenticated access to the local model server through the Ollama API, paving the way for persistent AI agent corruption.
LLVM/Clang 23.1 Released With AMD Zen 6 & NVIDIA Rigel Support, Partial C++26 Support
LLVM 23.1 was released today on-schedule as the first stable release of the LLVM 23 series as the H2'2026 update to this open-source compiler stack...
ToxNetV2 Linux Botnet Uses NVIDIA AI to Generate Shell and Remote SSH Attack Actions
ToxNetV2 is a Linux botnet that shows how artificial intelligence can move closer to real attack operations. Instead of using a model only to write text, the malware feeds system and botnet data into an AI service, then turns selected replies into proposed commands. That design gives operators a faster way to judge what to do next. The threat targets AArch64 Linux systems and uses a peer-to-peer design for command and control. Its wider toolkit includes host management, network scanning, self-propagation routines, and 17 network-attack launchers. The scanning and propagation activity can involve HTTP, Telnet, and SSH services, putting poorly secured internet-facing devices and servers in scope. Analysts at JOESecurity identified the AI-assisted controller while examining the malware’s code and operating flow.
A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw
Oasis Security has disclosed a weakness in NVIDIA NemoClaw that could let an attacker-controlled webpage take unauthenticated control of the local Ollama instance serving an AI agent and plant hidden instructions inside the model itself. The findings were shared with The Hacker News ahead of publication, and the report says Oasis Security reported them to NVIDIA's Product Security Incident
