6 min read
Vulnerabilities A server-side request forgery vulnerability in LMDeploy's vision-language image loader let attackers reach cloud instance metadata services and harvest full credentials. The first confirmed exploitation hit Sysdig's honeypot less than 13 hours after the CVE dropped.