AI Infrastructure
AI infrastructure explores GPUs, compute, training, inference and large-scale deployment. Articles follow platform evolution, architectural bottlenecks and the security implications of AI workloads.

CVE-2026-0768: Active Exploitation of Langflow, 360+ Attacks in Hours
The Langflow AI platform is under massive exploitation: over 360 attempts detected in hours leveraging critical vulnerability CVE-2026…

LLM Safety Rests on 50 Neurons: How Unit 42 Shatters the Myth of Distributed Alignment
Unit 42 research shows that safety mechanisms in large language models reside in less than 0.02% of neurons. The perturbation probing…

AI Honeypot: Real Attacks on LiteLLM and MCP Servers Reveal Three Patterns
Wiz Threat Research deployed AI/ML honeypots for 90 days and documented sustained, service-specific attacks. Three distinct patterns t…

GPUThor Bypasses NVIDIA ECC: Root Escalation in 1.1 Minutes on Workstation GPUs
The new GPUThor Rowhammer attack defeats SECDED ECC protection on NVIDIA Ampere RTX A4000-A6000 workstation cards. No patch is availab…

NVIDIA TensorRT: ONNX Parsing Flaw Enables RCE with CVSS 7.8
CVE-2026-24268 strikes the ONNX parser in NVIDIA TensorRT. A heap-based buffer overflow with CVSS 7.8, minimal user interaction, and a…

AMD Confirms Two TPM 2.0 Flaws: False Attestations on Ryzen from 3000 Series to AI
Two vulnerabilities in AMD's TPM 2.0 firmware jeopardize the hardware attestation chain on Ryzen processors. Patched firmware has been…

TeamPCP Exploits AI Supply Chain to Steal One Terabyte of Credentials
The TeamPCP campaign compromised GitHub Actions and PyPI packages between March and April 2026. Over 2,500 organizations potentially e…

CISA Adds CVE-2025-62593 to KEV Catalog: Ray at Risk of RCE
CISA added CVE-2025-62593 to its Known Exploited Vulnerabilities catalog on August 17, 2026. The critical flaw in the Ray framework ex…

Trivy and LiteLLM Compromised: 2,100+ Organizations Exposed via Security Tools
TeamPCP compromised the CI/CD pipelines of Trivy and LiteLLM between March 19 and March 24, 2026. Six confirmed breaches hit European…

NVIDIA Transformers4Rec: RCE with CVSS 4.3 — The Risk Scoring Gap
A deserialization flaw in NVIDIA Transformers4Rec enables remote code execution, yet the official CVE record rates it 4.3 MEDIUM with…

isolated-vm: C++ Binding Layer Bug Enables Sandbox Escape to Host RCE
A TOCTOU vulnerability in the Node.js isolated-vm library allows guest-to-host escape with potential RCE. Versions 6.2.0 and 7.0.1 pat…

TeamPCP/UNC6780: Six Enterprise Breaches From Trivy to LiteLLM
The TeamPCP/UNC6780 campaign compromised Trivy to poison LiteLLM on PyPI. According to Hudson Rock, six enterprise breaches resulted w…