Search

Find merged stories by title or summary.

Vulnerabilities & Patches
Emerging1 src

NVIDIA security advisory (AV26-957)

Serial number: AV26-957 Date: September 23, 2026 As of September 22, 2026, NVIDIA is affected by vulnerabilities in the following products: • Infrastructure Controller • Versions 0 to 1.9 • NeMo Speech • Versions 0.0 to 2.9 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. • Security Bulletin: NVIDIA Infrastructure Controller - September 2026 • Security Bulletin: NVIDIA NeMo Speech - September 2026 • NVIDIA Product Security NVIDIA security advisory (AV26-957) - Canadian Centre for Cyber Security

·Malware.news
Read →
Vulnerabilities & Patches
Emerging1 src

Security updates for Wednesday

Security updates have been issued by AlmaLinux (coreutils, postgresql18-postgis, and postgresql:16), Debian (memcached), Fedora (chromium, cyrus-imapd, dotnet10. 0, dotnet8. 0, dotnet9. 0, freeipmi, kernel, libxmp, perl-Net-DNS, and postgresql16-anonymizer), Mageia (cpio, diffutils, perl-Dancer2, and rest), Oracle (389-ds-base and firefox), Red Hat (opentelemetry-collector and osbuild-composer), SUSE (amazon-cloudwatch-agent, amazon-ssm-agent, apko, apptainer, bazel-rules-python-source, bind, cups, firefox, freeipmi, gdb, google-osconfig-agent, kernel, kyverno, libipa_hbac-devel, libsoup, libsoup-3_0-0, libtpms, openssl-certs, perl-Authen-SASL, php-composer2, python313-PyMuPDF, thunderbird, and util-linux), and Ubuntu (gzip, linux-aws, linux-aws-5. 15, linux-aws-fips, linux-nvidia-tegra-igx, linux-azure, linux-oracle, linux-azure-7. 0, linux-azure-fde-6.

·LWN.net
Read →
Vulnerabilities & Patches
Emerging1 src

NVIDIA Infrastructure Controller Hit by 14 Security Flaws Enabling Privilege Escalation and Code Execution

NVIDIA has released version 2.0 of its Infrastructure Controller to remediate 14 security vulnerabilities in the Linux-based infrastructure-management software, including a critical hard-coded credentials flaw that could enable remote compromise. The vulnerabilities affect versions 0 through 1.9, and NVIDIA is urging users to upgrade or clone the latest release from the project’s GitHub repository. NVIDIA’s security bulletin, issued on September 22, 2026, rates the flaws from medium to critical severity under CVSS v3.1. NVIDIA Infrastructure Controller Hit by 14 Security Flaws Collectively, the weaknesses could expose affected deployments to code execution, privilege escalation, data tampering, denial-of-service conditions , and information disclosure. The highest-rated issue, CVE-2026-65113, carries a CVSS score of 9. 8.

·CyberPress
Read →
Breaches & Ransomware
Emerging1 src

Lapsus$ Explained | The Hacking Group Behind Okta, Uber, Nvidia and Its Return

Lapsus$ is a hacking and extortion group first known for breaching Okta, Microsoft, Nvidia, Samsung, and Uber in 2021 and 2022 using social engineering rather than malware, and it has since reemerged as part of a larger collective called Scattered Lapsus$ Hunters. Unlike ransomware gangs that rely on encryption, Lapsus$ built its reputation on stealing source code and internal data, then threatening to leak it publicly unless the victim paid or complied with its demands. This tactic made it one of the most disruptive threat actors of the past few years despite reportedly being run largely by teenagers. That threat hasn’t gone away; it’s evolved.

·Malware.news
Read →
Vulnerabilities & Patches
Emerging1 src

NVIDIA Fixes Linux Component Flaws That Could Expose Sensitive System Information

NVIDIA released a security update for its Infrastructure Controller software for Linux, addressing 14 vulnerabilities that could let attackers access sensitive system information, execute code, alter data, or disrupt affected environments. The update, published in NVIDIA’s September 2026 Infrastructure Controller security bulletin, affects versions 0 through 1. 9. NVIDIA recommends that organizations clone or update the software to version 2. 0 or later to address all reported issues. Among the patched flaws is CVE-2026-65127, a medium-severity vulnerability caused by uncleared debug information. The issue carries a CVSS score of 4. 1 and is tracked as CWE-1258. An attacker with local access, high privileges, and favorable conditions could potentially retrieve sensitive system information left exposed through debugging artifacts.

·Cyber Security News
Read →
Vendors & Market
Emerging1 src

Open-Source NVIDIA "Nouveau" Driver Sees Patches For HDMI Deep Color Support

The Nouveau Linux kernel graphics driver for open-source NVIDIA driver support has new patches posted for enabling HDMI Deep Color support...

·Phoronix
Read →
Vendors & Market
Emerging1 src

ZLUDA Now Implements Some NVIDIA cuFFT APIs With hipFFT

ZLUDA as the open-source project working on CUDA for non-NVIDIA GPUs like AMD Radeon graphics cards now has implemented support for some of NVIDIA's core cuFFT APIs...

·Phoronix
Read →
Vendors & Market
Emerging1 src

Nvidia CEO rejects AI apocalypse warnings, claims they're overblown - Cybernews

Nvidia CEO rejects AI apocalypse warnings, claims they're overblown Cybernews

·Cybernews
Read →
Vendors & Market
Emerging1 src

Nvidia rejects RTX 5090 graphics card warranty claim over faded serial number - Cybernews

Nvidia rejects RTX 5090 graphics card warranty claim over faded serial number Cybernews

·Cybernews
Read →
Vulnerabilities & Patches
Emerging1 src

Security updates for Friday

Security updates have been issued by AlmaLinux (apr-util and qt6-qt5compat), Debian (libevent and ruby-rack), Fedora (bluez, corosync, curl, dokuwiki, grpcurl, libevent, and rest), Oracle (gstreamer1-plugins-bad-free, perl-DBI, python-urllib3, qt5-qtbase, qt6-qt5compat, and thunderbird), Red Hat (osbuild-composer), SUSE (azure-storage-azcopy, chromedriver, corosync, ggml-devel, helm, kernel, libmariadb-devel, libzypp, zypper, opensc, php7, tomcat10, and waylyrics), and Ubuntu (apache2, beets, glibc, kissfft, libebml, linux-nvidia-6. 17, php8. 1, php8. 3, php8. 5, and python2. 7, python3. 4, python3. 5, python3. 6, python3. 7, python3. 8, python3. 9, python3. 10, python3. 11, python3. 12, python3. 14).

·LWN.net
Read →
Vendors & Market
Emerging1 src

NVIDIA NVK Driver Lands Improvement To Help With Valve's Gamescope

Merged today for next quarter's Mesa 26. 3 release is an improvement for the open-source NVIDIA "NVK" Vulkan driver paired with the Nouveau kernel driver. This latest NVK improvement benefits usage of Valve's Gamescope micro-compositor and should help with performance during game recording and remote play...

·Phoronix
Read →
Vendors & Market
Emerging1 src

Experimental Patches Get Nouveau+NVK Working On NVIDIA DGX Spark GB10

Red Hat's David Airlie has managed another open-source graphics engineering feat... Getting the Nouveau reverse-engineered kernel graphics driver and Mesa NVK Vulkan driver running on the GB10 Grace Blackwell Superchip with the DGX Spark system...

·Phoronix
Read →
Vendors & Market
Emerging1 src

DLSS5VKLayer Wires Up NVIDIA DLSS 5 For Native Linux Games & Steam Play

An interesting new open-source project for those looking to make use of NVIDIA DLSS 5 on Linux is DLSS5VKLayer. The DLSS5VKLayer is a Linux Vulkan layer that works for both native Linux games as well as Steam Play (Proton) Windows games for experimental DLSS 5 support...

·Phoronix
Read →
Vulnerabilities & Patches
Emerging1 src

Chaotic Eclipse Released A PoC For NVIDIA GreenSection Memory Corruption Zero-Day

Chaotic Eclipse released GreenSection, a PoC exploit for an Nvidia GreenSection Memory Corruption Zero-Day Security researcher Chaotic Eclipse , also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting Nvidia. The researcher named the exploit GreenSection, it triggers a Memory Corruption flaw. The researcher disclosed a potential security vulnerability in NVIDIA’s Windows user-mode components. Several NVIDIA components share a global memory section that gives all users full read/write access. Although the software performs checks to prevent misuse, it reuses data from this shared memory at runtime, which can lead to an out-of-bounds memory write.

·Security Affairs
Read →
Vulnerabilities & Patches
Emerging1 src

Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits

The proof-of-concept (PoC) exploits lead to privilege escalation, spawning a shell with System privileges. The post Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits appeared first on SecurityWeek .

·SecurityWeek
Read →
Vendors & Market
Emerging1 src

Nouveau Preparations For HDMI 2.1 DSC, AMD HDMI FreeSync Fixes For Linux 7.4

Last week's set of DRM-Misc-Next changes submitted to DRM-Next with targeting the upcoming Linux 7. 4 kernel cycle features HDMI 2. 1 related work for both the AMDGPU kernel driver as well as the Nouveau open-source NVIDIA driver...

·Phoronix
Read →
Vulnerabilities & Patches
Emerging1 src

CrowdStrike Launches SafeMind Frontier Cybersecurity Models Built With NVIDIA Nemotron

CrowdStrike has launched SafeMind, a family of purpose-built cybersecurity models and agentic AI harnesses designed to help defenders identify, validate, and remediate threats inside the Falcon platform. Announced during Fal.Con 2026 in Las Vegas, SafeMind represents CrowdStrike’s move away from relying solely on general-purpose frontier models for security operations. The company said the new system was created specifically for cyber defense, combining offensive simulation, defensive response, and continuous model improvement within a closed-loop architecture. CrowdStrike Launches SafeMind Frontier Cybersecurity Models Developed by CrowdStrike’s newly created Cyber Superintelligence Lab, SafeMind is an agentic system that acts on security findings rather than simply producing alerts, summaries, or recommendations.

·CyberPress
Read →
Vendors & Market
Emerging1 src

NVIDIA Posts vGPU Manager & VFIO Variant Driver For Open-Source Nova

NVIDIA continues building out more functionality around the open-source, upstream Nova kernel graphics driver within the Linux kernel. Making it out to the mailing list this Saturday is a set of 13 patches for introducing a NVIDIA vGPU manager and VFIO variant driver...

·Phoronix
Read →
Vendors & Market
Emerging1 src

Nouveau Lands Display Fixes For NVIDIA Blackwell GPUs As It Works Toward HDMI 2.1

This week's Direct Rendering Manager (DRM) fixes that were merged ahead of Sunday's Linux 7.3-rc2 release contain a number of fixes to the open-source Nouveau driver's display support for current-generation NVIDIA Blackwell GPUs...

·Phoronix
Read →
Vendors & Market
Emerging1 src

Nvidia’s $12.9B Hugging Face deal could benefit enterprises

The chipmaker’s acquisition could eventually bring additional security resources and model evaluation tools to the platform, according to experts.

·Cybersecurity Dive
Read →
Vendors & Market
Emerging1 src

Nvidia Is Buying AI Platform Hugging Face for $13 Billion

The deal highlights Nvidia’s push to champion increasingly popular open-source AI models. The post Nvidia Is Buying AI Platform Hugging Face for $13 Billion appeared first on SecurityWeek .

·SecurityWeek
Read →
AI Security
Emerging1 src

Capsule Security Launches ‘AI Circuit Breaker’ to Stop Rogue Agents

New models, trained using NVIDIA Nemotron 3 Ultra, aim to catch rogue agent behavior before it executes, without the latency of large-model review. The post Capsule Security Launches ‘AI Circuit Breaker’ to Stop Rogue Agents appeared first on SecurityWeek .

·SecurityWeek
Read →
Vendors & Market
Emerging1 src

NVIDIA-Started Open Secure AI Alliance Moves To The Linux Foundation

Earlier this year NVIDIA led an effort with more than two dozen other companies to launch the Open Secure AI Alliance with a focus on keeping open-source AI models secure. The Open Secure AI Alliance today is transitioning from being stewarded by NVIDIA to becoming a Linux Foundation project...

·Phoronix
Read →
Vendors & Market
Emerging1 src

Is your monitor flickering, too? Users report bug in Nvidia's new GPU driver - Cybernews

Is your monitor flickering, too? Users report bug in Nvidia's new GPU driver Cybernews

·Cybernews
Read →
Vulnerabilities & Patches
Emerging1 src

GPUThor hardware attack can root Nvidia GPU systems

Hardware security researchers from University of Toronto have developed a new memory bit flipping technique that significantly improves on previously known attacks against GPU memory. The new method can defeat the error-correcting codes (ECC) defense used on enterprise Nvidia GPUs and can lead to root access on the underlying system. Dubbed GPUThor, the technique falls in a category of attacks known as Rowhammer that exploits the cell density of modern random access memory (RAM) chips. The original Rowhammer attack was demonstrated against DDR3 and DDR4 chips back in 2015 and relies on an older observation that tightly packed rows of memory cells can sometimes leak electrical charges to adjacent rows, flipping the stored bit values in those cells from 0 to 1 or the other way around.

·CSO Online
Read →
Vulnerabilities & Patches
Emerging1 src

Hackers can overwhelm Nvidia GPU ECC protections with GPUThor exploit and gain root access - Cybernews

Hackers can overwhelm Nvidia GPU ECC protections with GPUThor exploit and gain root access Cybernews

·Cybernews
Read →
AI Security
Emerging1 src

NVIDIA NemoClaw flaw can hijack AI agents online - Cybernews

NVIDIA NemoClaw flaw can hijack AI agents online Cybernews

·Cybernews
Read →
Vulnerabilities & Patches
Emerging1 src

New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access

Academic researchers have disclosed a Rowhammer attack impacting NVIDIA workstation GPUs with GDDR6 memory that defeats error correction codes (ECC), the mitigation NVIDIA recommends against GPU Rowhammer, and enables denial-of-service (DoS) and privilege escalation to a root shell. Dubbed GPUThor, the attack was developed by researchers at the University of Toronto, who hammered four DRAM

·The Hacker News
Read →
Threat Actors & Campaigns
Emerging1 src

Nvidia’s breach might help cybercriminals run malware campaigns - TechRepublic

Nvidia’s breach might help cybercriminals run malware campaigns TechRepublic

·TechRepublic Cybersecurity
Read →
Vulnerabilities & Patches
Emerging1 src

New GPUThor attack defeats NVIDIA ECC protection for root access

A newly disclosed Rowhammer attack called GPUThor can bypass error-correcting code (ECC) protections on NVIDIA GPUs, enabling denial-of-service (DoS) and root-level privilege escalation. [... ]

·BleepingComputer
Read →
Vulnerabilities & Patches
Emerging1 src

Adobe and Nvidia Patch Dozens of Vulnerabilities

Adobe and Nvidia each published several advisories, including ones that address critical vulnerabilities in their products. The post Adobe and Nvidia Patch Dozens of Vulnerabilities appeared first on SecurityWeek .

·SecurityWeek
Read →
Vulnerabilities & Patches
Emerging1 src

NemoClaw’s AI can be poisoned through a browser tab

A vulnerability affecting Nvidia’s NemoClaw could let an attacker gain control of the local Ollama model server through a single malicious website visit on the victim’s machine. According to a Cyera research, the flaw could give attackers unauthenticated access to the server, allowing them to plant instructions into the model that persist across future conversations. The attacker doesn’t directly connect to the victim’s Ollama server from the internet. Instead, the malicious webpage tricks the browser into reaching the locally running Ollama API through DNS rebinding. Once that happens, the model’s chat template, a layer that controls how messages are presented to the model, is manipulated to add malicious instructions to the agent’s system prompts.

·CSO Online
Read →
Vulnerabilities & Patches
Emerging1 src

GPUThor Rowhammer attack beats ECC on NVIDIA workstation GPUs

University of Toronto researchers have developed a new Rowhammer technique named GPUThor that can overwhelm error-correcting memory on several NVIDIA workstation GPUs, enabling crashes and even privilege escalation to root. The attack produces up to 23,500 times more bit flips than the first GPU Rowhammer attack, bringing GPU attack rates close to those seen on … The post GPUThor Rowhammer attack beats ECC on NVIDIA workstation GPUs appeared first on CyberInsider .

·CyberInsider
Read →
Vulnerabilities & Patches
Emerging1 src

CVE-2026-65105 - NVIDIA NemoClaw Inference Server Authentication Bypass

CVE ID : CVE-2026-65105 Published : Aug. 25, 2026, 8:15 p. m. • 57 minutes ago Description : NVIDIA NemoClaw for Linux contains a vulnerability in its inference server setup, where a remote attacker may access the inference service without authentication. A successful exploit of this vulnerability may lead to information disclosure and denial of service. Severity: 8.1 • HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

·CVEFeed
Read →
Vulnerabilities & Patches
Emerging1 src

CVE-2026-65088 - NVIDIA NemoClaw Sensitive Information Disclosure

CVE ID : CVE-2026-65088 Published : Aug. 25, 2026, 8:15 p. m. • 57 minutes ago Description : NVIDIA NemoClaw contains a vulnerability where an attacker could cause invocation of process using visible sensitive information. A successful exploit of this vulnerability might lead to information disclosure. Severity: 5.5 • MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

·CVEFeed
Read →
Vulnerabilities & Patches
Emerging1 src

CVE-2026-65087 - NVIDIA NemoClaw Credential Improper Authorization Vulnerability

CVE ID : CVE-2026-65087 Published : Aug. 25, 2026, 8:15 p. m. • 57 minutes ago Description : NVIDIA NemoClaw contains a vulnerability where an attacker could cause insufficiently protected credentials . A successful exploit of this vulnerability might lead to information disclosure and data tampering. Severity: 5.6 • MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

·CVEFeed
Read →
AI Security
Emerging1 src

Finding Nemo(Claw): Networking Issue Allows for LLM Poisoning in OpenClaw

Attackers can exploit a security bug in NVIDIA's tool to gain unauthenticated access to the local model server through the Ollama API, paving the way for persistent AI agent corruption.

·Dark Reading
Read →
Vendors & Market
Emerging1 src

LLVM/Clang 23.1 Released With AMD Zen 6 & NVIDIA Rigel Support, Partial C++26 Support

LLVM 23.1 was released today on-schedule as the first stable release of the LLVM 23 series as the H2'2026 update to this open-source compiler stack...

·Phoronix
Read →
Threat Actors & Campaigns
Emerging1 src

ToxNetV2 Linux Botnet Uses NVIDIA AI to Generate Shell and Remote SSH Attack Actions

ToxNetV2 is a Linux botnet that shows how artificial intelligence can move closer to real attack operations. Instead of using a model only to write text, the malware feeds system and botnet data into an AI service, then turns selected replies into proposed commands. That design gives operators a faster way to judge what to do next. The threat targets AArch64 Linux systems and uses a peer-to-peer design for command and control. Its wider toolkit includes host management, network scanning, self-propagation routines, and 17 network-attack launchers. The scanning and propagation activity can involve HTTP, Telnet, and SSH services, putting poorly secured internet-facing devices and servers in scope. Analysts at JOESecurity identified the AI-assisted controller while examining the malware’s code and operating flow.

·Cyber Security News
Read →
AI Security
Emerging1 src

A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw

Oasis Security has disclosed a weakness in NVIDIA NemoClaw that could let an attacker-controlled webpage take unauthenticated control of the local Ollama instance serving an AI agent and plant hidden instructions inside the model itself. The findings were shared with The Hacker News ahead of publication, and the report says Oasis Security reported them to NVIDIA's Product Security Incident

·The Hacker News
Read →