ThreatCluster
  • Feed
  • Dashboard
  • Saved
THREAT HUNTING
  • Domains
  • IP Addresses
  • File Hashes
  • CVEs
THREAT INTELLIGENCE
  • APT Groups
  • Ransomware Groups
  • Malware Families
  • Attack Types
  • MITRE ATT&CK
  • Security Standards
  • Vulnerability Types
BUSINESS INTELLIGENCE
  • Companies
  • Industry Sectors
  • Security Vendors
  • Government Agencies
  • Countries
  • Platforms
Home / Feed / Article

NVIDIA Triton Bugs Let Unauthenticated Attackers Execute Code and Hijack AI Servers

Threat Score:
50
The Hacker News
1 day ago
Part of cluster #1639

Overview

A newly disclosed set of security flaws inNVIDIA's Triton Inference Serverfor Windows and Linux, an open-source platform for running artificial intelligence (AI) models at scale, could be exploited to take over susceptible servers. "When chained together, these flaws can potentially allow a remote, unauthenticated attacker to gain complete control of the server, achieving remote code execution (RCE)," Wiz researchers Ronen Shustin and Nir Ohfeldsaidin a report published today. Thevulnerabilities...

Continue Reading on Original Site

Related Articles

5 articles
1

Destructive Ransomware is Outpacing Your Recovery Plan

Morphisec News • 5 hours ago

Discover why data recovery is the biggest breach cost driver—and how you can foritfy your ransomware recovery plan.

Score
89
Read more
2
CVE-2025-54466: Apache OFBiz: RCE Vulnerability in scrum plugin

CVE-2025-54466: Apache OFBiz: RCE Vulnerability in scrum plugin

OSS Security • 4 hours ago

oss-secmailing list archives CVE-2025-54466: Apache OFBiz: RCE Vulnerability in scrum plugin Current thread: CVE-2025-54466: Apache OFBiz: RCE Vulnerability in scrum pluginNicolas Malin (Aug 05)

Score
88
Read more
3

Microsoft’s Project Ire Autonomously Reverse Engineers Software to Find Malware

SecurityWeek • 2 hours ago

Microsoft has unveiled Project Ire, a prototype autonomous AI agent that can analyze any software file to determine if it’s malicious.

Score
87
Read more
4

Microsoft Launches Zero-Day Quest Hacking Contest with Rewards Up to $5 Million

GB Hackers • 2 hours ago

Microsoft Launches Zero-Day Quest Hacking Contest with Rewards Up to $5 Million Microsoft has unveiled the return of its groundbreaking Zero Day Quest initiative, escalating the stakes in cybersecurity research with a staggering total bounty pool of up to $5 million. Building on the success of last year’s inaugural event, which offered $4 million in awards and garnered overwhelming participation from the global security community, this year’s program intensifies focus on high-impact vulnerabilit

Score
84
Read more
5

APT36 Targets Indian Government: Credential Theft Campaign Uncovered

GB Hackers • 5 hours ago

APT36 Targets Indian Government: Credential Theft Campaign Uncovered A sophisticated phishing campaign attributed with medium confidence to the Pakistan-linked APT36 group, also known as Transparent Tribe or Mythic Leopard, has been uncovered targeting Indian defense organizations and government entities. This operation employs typo-squatted domains that mimic official Indian government platforms, such as mail.mgovcloud.in and virtualeoffice.cloud, to deceive users into surrendering credentials.

Score
82
Read more

Save to Folder

Choose a folder to save this article:

Article Intelligence

Key entities and indicators for this article

CVES
CVE-2025-23310
CVE-2025-23311
CVE-2025-23317
CVE-2025-23319
CVE-2025-23320
ATTACK TYPES
Data Manipulation
Denial of Service
Information Disclosure
Remote Code Execution
VULNERABILITIES
Denial of Service
Information Disclosure
RCE
Remote Code Execution
COMPANIES
NVIDIA
Wiz
SECURITY VENDORS
Wiz
PLATFORMS
Linux
Triton Inference Server
Windows
APT GROUPS
APT41
RANSOMWARE
Python
MALWARE
Leverage
Triton
MITRE ATT&CK
T1003
T1053
T1059.001
T1059.006
T1060
INDUSTRIES
Artificial Intelligence
Technology
ARTICLE INFORMATION
Article #8318
Published 1 day ago
The Hacker News

We use cookies

We use cookies and similar technologies to enhance your experience, analyse site usage, and assist in our marketing efforts.

Cookie Settings

Essential Cookies

Required for the website to function. Cannot be disabled.

  • Session management and authentication
  • Security and fraud prevention
  • Cookie consent preferences

Analytics Cookies

Help us understand how visitors interact with our website.

  • Plausible Analytics - Privacy-focused usage statistics
  • PostHog - Product analytics and feature tracking
  • Page views and user journey analysis

Performance Cookies

Help us monitor and improve website performance.

  • Page load time monitoring
  • Error tracking and debugging
  • Performance optimisation

Marketing Cookies

Used to track visitors across websites for marketing purposes.

  • Conversion tracking
  • Remarketing campaigns
  • Social media integration