Oasis Security disclosed CVE-2026-65105, a DNS rebinding flaw in NVIDIA's NemoClaw stack that let a single malicious webpage seize control of a local Ollama server and plant a hidden, persistent instruction inside the model's chat template.
Oasis Security disclosed CVE-2026-65105, a DNS rebinding flaw in NVIDIA's NemoClaw stack that let a single malicious webpage seize control of a local Ollama server and plant a hidden, persistent instruction inside the model's chat template.
University of Toronto researchers presented GPUBreach at Black Hat 2026 — a Rowhammer attack that escalates from an unprivileged CUDA kernel to a host root shell, bypassing IOMMU, threatening shared AI cloud GPU infrastructure.
NVIDIA and 36 industry partners — including Microsoft, Cisco, CrowdStrike, and Hugging Face — launched the Open Secure AI Alliance on July 27, 2026, releasing the NOOA framework for testing and auditing AI agent behaviour. The coalition cites recent autonomous agent attacks as the catalyst.