AI Infrastructure
AI infrastructure explores GPUs, compute, training, inference and large-scale deployment. Articles follow platform evolution, architectural bottlenecks and the security implications of AI workloads.

Interrupt Injection: MIT Attack Bypasses Spectre v2 Defenses on Intel and AMD
MIT CSAIL researchers Daniël Trujillo and Mengjia Yan presented the Interrupt Injection technique at Black Hat USA 2026, demonstrating…

AMD Confirms Two High-Severity TPM 2.0 Flaws in Ryzen: Fixes Were Circulating Since May 2026
AMD published advisory AMD-SB-7064 on August 11, 2026, disclosing two high-severity TPM 2.0 vulnerabilities (CVE-2026-6726 and CVE-202…

NVIDIA Transformers4Rec Exposed to RCE: ML Checkpoint Turns Weapon
A deserialization flaw in NVIDIA's ML library enables remote code execution via malicious checkpoints. A documented discrepancy betwee…

Flowise Removes Airtable and CSV Agents After Critical RCE (CVSS 9.4)
The low-code AI orchestration platform Flowise has entirely removed its AirtableAgent and CSVAgent components to address an unauthenti…

TeamPCP Compromises LiteLLM: 434,000 Pipelines Exposed in 40 Minutes
TeamPCP injected malicious LiteLLM packages onto PyPI for 40 minutes. CloudSEK estimates 2,500+ organizations exposed. Stolen credenti…

Flowise Pre-Auth RCE, CVSS 9.8: Update Immediately to 3.1.3
ZDI-26-546 discloses a critical flaw in the low-code Flowise platform. The Airtable_Agent component executes Python code without valid…

TONTOU: The AMD Attack Exposing the Gap Between Linux Patches and Vendor Disclosure
The TONTOU attack bypasses Spectre-v2 mitigations on AMD Zen 1–4 processors. The Linux kernel received a fix on June 2, 2026, but AMD'…

CVE-2025-23266: NVIDIA Container Escape in Three Lines of Dockerfile
NVIDIA's GPU orchestration toolkit contains a critical vulnerability enabling container escape and privilege escalation on cloud AI in…

Backdoored LiteLLM on PyPI: Malware Triggers on Python Startup Alone
On March 24, 2026, two malicious LiteLLM versions exfiltrated credentials from over 50 categories via a .pth mechanism. The compromise…

Intel and AMD Patch 70 Flaws: Two Critical CVSS 9.3 and 9.2 Bugs in GPU Drivers
On May 13, 2026, Intel and AMD released 28 advisories covering 69 vulnerabilities. Two critical flaws hit chip software drivers, not t…

RufRoot: The AI Vulnerability That Survives the Patch — 233 Tools Exposed and Persistent Memory Poisoning
CVE-2026-59726 in Ruflo exposes 233 MCP tools without authentication, enabling RCE, LLM API key theft, and persistent memory poisoning…

NVIDIA NVTabular: RCE via Pickle, CVE-2026-24237 Rated CVSS 7.8
A deserialization flaw in NVIDIA NVTabular enables remote code execution through malicious pickle files. User interaction is required;…