01
Critical
news
Agent Security
Cross-Industry
Dark Reading·Aug 25, 19:50 UTC
Attackers can exploit a security bug in NVIDIA's tool to gain unauthenticated access to the local model server through the Ollama API, paving the way for persistent AI agent corruption.
Read full report →
02
High
news
Agent Security
Cross-Industry
The Hacker News·Aug 25, 14:07 UTC
Oasis Security has disclosed a weakness in NVIDIA NemoClaw that could let an attacker-controlled webpage take unauthenticated control of the local Ollama instance serving an AI agent and plant hidden instructions inside the model itself. The findings were shared with The Hacker News ahead of publication, and the report says Oasis Security reported them to NVIDIA's Product Security Incident
Read full report →
03
Notable
news
MCP Security
Cross-Industry
The Hacker News·Aug 25, 12:43 UTC
Marimo has addressed a high-severity security flaw in its notebook software that allowed an attacker to execute an attacker-supplied Model Context Protocol (MCP) command in a specially crafted notebook, according to VulnCheck's CVE Numbering Authority (CNA) record. The CNA record says the command can run as a local subprocess when the notebook is opened in edit mode.
Read full report →