CVE-2024-0132
published 2024-09-26CVE-2024-0132: NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with default configuration where a…
PriorityP267high8.3CVSS 3.1
AVNACHPRNUIRSCCHIHAH
EXPLOIT
EPSS
37.05%
98.3th percentile
NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with default configuration where a specifically crafted container image may gain access to the host file system. This does not impact use cases where CDI is used. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | nvidia_nvidia-container-toolkit | >= 0 < 1.16.2 | 1.16.2 |
| msrc | azure_kubernetes_service_node_on_azure_linux | — | — |
| msrc | azure_kubernetes_service_node_on_ubuntu_linux | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| nvidia | container_toolkit | — | — |
| nvidia | gpu_operator | — | — |
| nvidia | nvidia_container_toolkit | < 1.16.2 | 1.16.2 |
| nvidia | nvidia_gpu_operator | < 24.6.2 | 24.6.2 |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for symlinks or directories planted at /usr/local/cuda/compat/ matching the glob pattern lib*.so.* inside container images, as the exploit plants directories instead of regular files at this path to manipulate the xglob resolution. ↗
- →Prioritize patching container hosts running NVIDIA Container Toolkit versions ≤1.16.1 that are also pulling images from publicly writable or external/untrusted repositories, as these represent the highest-risk exploitation scenario. ↗
- →The TOCTOU vulnerability is triggered during the prestart OCI hook phase before container security boundaries are fully established; monitor for anomalous filesystem operations (symlink/directory creation under cuda compat paths) occurring during this early container initialization window. ↗
- →CDI (Container Device Interface) mode bypasses the vulnerable code path entirely; environments using CDI (e.g., Podman with native CDI support) are not affected and can be used as a compensating control. ↗
- ·The vulnerability only affects NVIDIA Container Toolkit when used with default configuration (non-CDI mode). Deployments using CDI are not impacted. ↗
- ·The original patch for CVE-2024-0132 did not fully resolve the issue; a bypass was separately tracked as CVE-2025-23359. Both are addressed in NVIDIA Container Toolkit version 1.17.4. ↗
- ·While Docker is the primary focus, Containerd (Kubernetes) and CRI-O runtimes are also affected by CVE-2024-0132; Podman via CDI is not affected. ↗
CVSS provenance
nvdv3.18.3HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
vendor_msrc9.0CRITICAL
vendor_redhat9.0CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
CVE-2024-0132: FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One
vendor_msrc·2024-10-08·CVSS 9.0
CVE-2024-0132 [CRITICAL] CVE-2024-0132: FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
[email protected]: [email protected]
Customer Action Required: Yes
Microsoft
NVIDIA: CVE-2024-0132 Container Toolkit 1.16.1 and Earlier Time-of-check Time-of Use Vulnerability
vendor_msrc·2024-10-08·CVSS 8.3
CVE-2024-0132 [CRITICAL] CWE-367 NVIDIA: CVE-2024-0132 Container Toolkit 1.16.1 and Earlier Time-of-check Time-of Use Vulnerability
NVIDIA: CVE-2024-0132 Container Toolkit 1.16.1 and Earlier Time-of-check Time-of Use Vulnerability
NIST NVD Details: https://nvd.nist.gov/vuln/detail/CVE-2024-0132
FAQ: What actions do customers need to take to protect themselves from this vulnerability?
Customers with Ubuntu Linux or Azure Linux based Azure Kubernetes Service (AKS) Node Pools using NVIDIA GPU driver configurations are affected by this vulnerability. Please see below for details on how to update your resources to be protected against this vulnerability.
Customers with Azure Linux based AKS Node Pool resources must manually install AKS Node image version 2024.1009.1 to be protected against this vulnerability by running the following CLI command:
tdnf install https://packages.microsoft.com/cbl-mariner/2.0/prod/base/x86_64
Red Hat
nvidia-container-toolkit: Time-of-check Time-of-use (TOCTOU) Race Condition in NVIDIA Container toolkit
vendor_redhat·2024-09-26·CVSS 9.0
CVE-2024-0132 [CRITICAL] CWE-367 nvidia-container-toolkit: Time-of-check Time-of-use (TOCTOU) Race Condition in NVIDIA Container toolkit
nvidia-container-toolkit: Time-of-check Time-of-use (TOCTOU) Race Condition in NVIDIA Container toolkit
NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with default configuration where a specifically crafted container image may gain access to the host file system. This does not impact use cases where CDI is used. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
A flaw was found in the NVIDIA Container Toolkit. Affected versions contain a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with the default configuration, where a specifically crafted container image may gain access to the host file system. Thi
Palo Alto
PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2024-09-04·CVSS 6.0
CVE-2022-22965 [MEDIUM] PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2010-1622, CVE-2015-7552, CVE-2018-16840, CVE-2019-7639, CVE-2020-17049, CVE-2020-7774, CVE-2021-0131, CVE-2021-0132, CVE-2021-0133, CVE-2021-0134, CVE-2021-4044, CVE-2021-4160, CVE-2021-41773, CVE-2022-1343, CVE-2022-21449, CVE-2022-2274, CVE-2022-22963, CVE-2022-22965, CVE-2022-24697, CVE-2022-32207, CVE-2022-3358, CVE-2022-3996, CVE-2022-40664, CVE-2022-44792, CVE-2022-44793, CVE-2023-1255, CVE-2023-22809, CVE-2023-23919, CVE-2023-3341, CVE-2023-4236, CVE-2023-4863, CVE-2023-51767
Affected products: PAN-OS
OSV
NVIDIA Container Toolkit contains a Time-of-check Time-of-Use (TOCTOU) vulnerability in github.com/NVIDIA/nvidia-container-toolkit
osv·2024-11-04
CVE-2024-0132 NVIDIA Container Toolkit contains a Time-of-check Time-of-Use (TOCTOU) vulnerability in github.com/NVIDIA/nvidia-container-toolkit
NVIDIA Container Toolkit contains a Time-of-check Time-of-Use (TOCTOU) vulnerability in github.com/NVIDIA/nvidia-container-toolkit
NVIDIA Container Toolkit contains a Time-of-check Time-of-Use (TOCTOU) vulnerability in github.com/NVIDIA/nvidia-container-toolkit
GHSA
NVIDIA Container Toolkit contains a Time-of-check Time-of-Use (TOCTOU) vulnerability
ghsa·2024-10-29
CVE-2024-0132 [CRITICAL] CWE-367 NVIDIA Container Toolkit contains a Time-of-check Time-of-Use (TOCTOU) vulnerability
NVIDIA Container Toolkit contains a Time-of-check Time-of-Use (TOCTOU) vulnerability
NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with default configuration where a specifically crafted container image may gain access to the host file system. This does not impact use cases where CDI is used. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
OSV
NVIDIA Container Toolkit contains a Time-of-check Time-of-Use (TOCTOU) vulnerability
osv·2024-10-29
CVE-2024-0132 [CRITICAL] NVIDIA Container Toolkit contains a Time-of-check Time-of-Use (TOCTOU) vulnerability
NVIDIA Container Toolkit contains a Time-of-check Time-of-Use (TOCTOU) vulnerability
NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with default configuration where a specifically crafted container image may gain access to the host file system. This does not impact use cases where CDI is used. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
No detection rules found.
Wiz
What Is AI Threat Intelligence? Real Risks to AI Systems Explained | Wiz
blogs_wiz·2025-12-23
What Is AI Threat Intelligence? Real Risks to AI Systems Explained | Wiz
## What is AI threat intelligence?
AI threat intelligence is the practice of understanding, tracking, and operationalizing threats that target AI systems – along with using advanced analytics to scale how that intelligence is produced and applied. At its core, it focuses on how attackers abuse, compromise, or exploit AI models, data pipelines, and the cloud infrastructure that supports them.
This distinguishes AI threat intelligence from adjacent disciplines like threat detection or SOC automation . While detection focuses on identifying suspicious activity as it occurs, threat intelligence is concerned with patterns, techniques, and trends – how threats evolve over time, which systems they target, and what conditions make those attacks viable in real environments.
AI systems require th
Wiz
What Is AI Threat Intelligence? Real Risks to AI Systems Explained | Wiz
blogs_wiz·2025-12-23
What Is AI Threat Intelligence? Real Risks to AI Systems Explained | Wiz
## What is AI threat intelligence?
AI threat intelligence is the practice of understanding, tracking, and operationalizing threats that target AI systems – along with using advanced analytics to scale how that intelligence is produced and applied. At its core, it focuses on how attackers abuse, compromise, or exploit AI models, data pipelines, and the cloud infrastructure that supports them.
This distinguishes AI threat intelligence from adjacent disciplines like threat detection or SOC automation. While detection focuses on identifying suspicious activity as it occurs, threat intelligence is concerned with patterns, techniques, and trends – how threats evolve over time, which systems they target, and what conditions make those attacks viable in real environments.
AI systems require thi
Wiz
Container Security Scanning: From Detection to Deployment | Wiz
blogs_wiz·2025-11-14
Container Security Scanning: From Detection to Deployment | Wiz
## What is container security scanning?
Container security scanning is an automated process that analyzes container images and running containers to identify vulnerabilities, misconfigurations, and security threats before deployment. This proactive approach prevents potential breaches while maintaining development velocity.
Modern containerized environments create unique security challenges that traditional tools can't address, with one report indicating that 67% of organizations have delayed application deployment due to container security concerns. Containers bundle application code with dependencies, creating new attack vectors that require specialized detection methods. Integrating scanning into CI/CD pipelines ensures vulnerabilities are caught early without slowing development cycl
Wiz
Container Security Scanning: From Detection to Deployment | Wiz
blogs_wiz·2025-11-14
Container Security Scanning: From Detection to Deployment | Wiz
## What is container security scanning?
Container security scanning is an automated process that analyzes container images and running containers to identify vulnerabilities, misconfigurations, and security threats before deployment. This proactive approach prevents potential breaches while maintaining development velocity.
Modern containerized environments create unique security challenges that traditional tools can't address, with one report indicating that 67% of organizations have delayed application deployment due to container security concerns. Containers bundle application code with dependencies, creating new attack vectors that require specialized detection methods. Integrating scanning into CI/CD pipelines ensures vulnerabilities are caught early without slowing development cycl
Wiz
Container Security Scanning: From Detection to Deployment | Wiz
blogs_wiz·2025-11-14
Container Security Scanning: From Detection to Deployment | Wiz
## What is container security scanning?
Container security scanning is an automated process that analyzes container images and running containers to identify vulnerabilities, misconfigurations, and security threats before deployment. This proactive approach prevents potential breaches while maintaining development velocity.
Modern containerized environments create unique security challenges that traditional tools can't address, with one report indicating that 67% of organizations have delayed application deployment due to container security concerns. Containers bundle application code with dependencies, creating new attack vectors that require specialized detection methods. Integrating scanning into CI/CD pipelines ensures vulnerabilities are caught early without slowing development cycl
Wiz
Container Security Scanning: From Detection to Deployment | Wiz
blogs_wiz·2025-11-14
Container Security Scanning: From Detection to Deployment | Wiz
## What is container security scanning?
Container security scanning is an automated process that analyzes container images and running containers to identify vulnerabilities, misconfigurations, and security threats before deployment. This proactive approach prevents potential breaches while maintaining development velocity.
Modern containerized environments create unique security challenges that traditional tools can't address, with one report indicating that 67% of organizations have delayed application deployment due to container security concerns. Containers bundle application code with dependencies, creating new attack vectors that require specialized detection methods. Integrating scanning into CI/CD pipelines ensures vulnerabilities are caught early without slowing development cycl
Wiz
Container Security Scanning: From Detection to Deployment | Wiz
blogs_wiz·2025-11-14
Container Security Scanning: From Detection to Deployment | Wiz
## What is container security scanning?
Container security scanning is an automated process that analyzes container images and running containers to identify vulnerabilities, misconfigurations, and security threats before deployment. This proactive approach prevents potential breaches while maintaining development velocity.
Modern containerized environments create unique security challenges that traditional tools can't address, with one report indicating that 67% of organizations have delayed application deployment due to container security concerns. Containers bundle application code with dependencies, creating new attack vectors that require specialized detection methods. Integrating scanning into CI/CD pipelines ensures vulnerabilities are caught early without slowing development cycl
Wiz
Container Security Scanning: From Detection to Deployment | Wiz
blogs_wiz·2025-11-14
Container Security Scanning: From Detection to Deployment | Wiz
## What is container security scanning?
Container security scanning is an automated process that analyzes container images and running containers to identify vulnerabilities, misconfigurations, and security threats before deployment. This proactive approach prevents potential breaches while maintaining development velocity.
Modern containerized environments create unique security challenges that traditional tools can't address, with one report indicating that 67% of organizations have delayed application deployment due to container security concerns. Containers bundle application code with dependencies, creating new attack vectors that require specialized detection methods. Integrating scanning into CI/CD pipelines ensures vulnerabilities are caught early without slowing development cycl
Wiz
Container Security Scanning: From Detection to Deployment | Wiz
blogs_wiz·2025-11-14
Container Security Scanning: From Detection to Deployment | Wiz
## What is container security scanning?
Container security scanning is an automated process that analyzes container images and running containers to identify vulnerabilities, misconfigurations, and security threats before deployment. This proactive approach prevents potential breaches while maintaining development velocity.
Modern containerized environments create unique security challenges that traditional tools can't address, with one report indicating that 67% of organizations have delayed application deployment due to container security concerns. Containers bundle application code with dependencies, creating new attack vectors that require specialized detection methods. Integrating scanning into CI/CD pipelines ensures vulnerabilities are caught early without slowing development cycl
Wiz
Container Security Scanning: From Detection to Deployment | Wiz
blogs_wiz·2025-11-14
Container Security Scanning: From Detection to Deployment | Wiz
## What is container security scanning?
Container security scanning is an automated process that analyzes container images and running containers to identify vulnerabilities, misconfigurations, and security threats before deployment. This proactive approach prevents potential breaches while maintaining development velocity.
Modern containerized environments create unique security challenges that traditional tools can't address, with one report indicating that 67% of organizations have delayed application deployment due to container security concerns. Containers bundle application code with dependencies, creating new attack vectors that require specialized detection methods. Integrating scanning into CI/CD pipelines ensures vulnerabilities are caught early without slowing development cycl
Wiz
Container Security Scanning: From Detection to Deployment | Wiz
blogs_wiz·2025-11-14
Container Security Scanning: From Detection to Deployment | Wiz
## What is container security scanning?
Container security scanning is an automated process that analyzes container images and running containers to identify vulnerabilities, misconfigurations, and security threats before deployment. This proactive approach prevents potential breaches while maintaining development velocity.
Modern containerized environments create unique security challenges that traditional tools can't address, with one report indicating that 67% of organizations have delayed application deployment due to container security concerns. Containers bundle application code with dependencies, creating new attack vectors that require specialized detection methods. Integrating scanning into CI/CD pipelines ensures vulnerabilities are caught early without slowing development cycl
Wiz
Container Security Scanning: From Detection to Deployment | Wiz
blogs_wiz·2025-11-14
Container Security Scanning: From Detection to Deployment | Wiz
## What is container security scanning?
Container security scanning is an automated process that analyzes container images and running containers to identify vulnerabilities, misconfigurations, and security threats before deployment. This proactive approach prevents potential breaches while maintaining development velocity.
Modern containerized environments create unique security challenges that traditional tools can't address, with one report indicating that 67% of organizations have delayed application deployment due to container security concerns. Containers bundle application code with dependencies, creating new attack vectors that require specialized detection methods. Integrating scanning into CI/CD pipelines ensures vulnerabilities are caught early without slowing development cycl
Wiz
Container Security Scanning: From Detection to Deployment | Wiz
blogs_wiz·2025-11-14
Container Security Scanning: From Detection to Deployment | Wiz
## What is container security scanning?
Container security scanning is an automated process that analyzes container images and running containers to identify vulnerabilities, misconfigurations, and security threats before deployment. This proactive approach prevents potential breaches while maintaining development velocity.
Modern containerized environments create unique security challenges that traditional tools can't address, with one report indicating that 67% of organizations have delayed application deployment due to container security concerns. Containers bundle application code with dependencies, creating new attack vectors that require specialized detection methods. Integrating scanning into CI/CD pipelines ensures vulnerabilities are caught early without slowing development cycl
Wiz
Container Security Scanning: From Detection to Deployment | Wiz
blogs_wiz·2025-11-14
Container Security Scanning: From Detection to Deployment | Wiz
## What is container security scanning?
Container security scanning is an automated process that analyzes container images and running containers to identify vulnerabilities, misconfigurations, and security threats before deployment. This proactive approach prevents potential breaches while maintaining development velocity.
Modern containerized environments create unique security challenges that traditional tools can't address, with one report indicating that 67% of organizations have delayed application deployment due to container security concerns. Containers bundle application code with dependencies, creating new attack vectors that require specialized detection methods. Integrating scanning into CI/CD pipelines ensures vulnerabilities are caught early without slowing development cycl
Wiz
Container Security Scanning: From Detection to Deployment | Wiz
blogs_wiz·2025-11-14
Container Security Scanning: From Detection to Deployment | Wiz
## What is container security scanning?
Container security scanning is an automated process that analyzes container images and running containers to identify vulnerabilities, misconfigurations, and security threats before deployment. This proactive approach prevents potential breaches while maintaining development velocity.
Modern containerized environments create unique security challenges that traditional tools can't address, with one report indicating that 67% of organizations have delayed application deployment due to container security concerns. Containers bundle application code with dependencies, creating new attack vectors that require specialized detection methods. Integrating scanning into CI/CD pipelines ensures vulnerabilities are caught early without slowing development cycl
Wiz
Container Security Scanning: From Detection to Deployment | Wiz
blogs_wiz·2025-11-14
Container Security Scanning: From Detection to Deployment | Wiz
## What is container security scanning?
Container security scanning is an automated process that analyzes container images and running containers to identify vulnerabilities, misconfigurations, and security threats before deployment. This proactive approach prevents potential breaches while maintaining development velocity.
Modern containerized environments create unique security challenges that traditional tools can't address, with one report indicating that 67% of organizations have delayed application deployment due to container security concerns. Containers bundle application code with dependencies, creating new attack vectors that require specialized detection methods. Integrating scanning into CI/CD pipelines ensures vulnerabilities are caught early without slowing development cycl
Wiz
Container Security Scanning: From Detection to Deployment | Wiz
blogs_wiz·2025-11-14
Container Security Scanning: From Detection to Deployment | Wiz
## What is container security scanning?
Container security scanning is an automated process that analyzes container images and running containers to identify vulnerabilities, misconfigurations, and security threats before deployment. This proactive approach prevents potential breaches while maintaining development velocity.
Modern containerized environments create unique security challenges that traditional tools can't address, with one report indicating that 67% of organizations have delayed application deployment due to container security concerns. Containers bundle application code with dependencies, creating new attack vectors that require specialized detection methods. Integrating scanning into CI/CD pipelines ensures vulnerabilities are caught early without slowing development cycl
Wiz
Container Security Scanning: From Detection to Deployment | Wiz
blogs_wiz·2025-11-14
Container Security Scanning: From Detection to Deployment | Wiz
## What is container security scanning?
Container security scanning is an automated process that analyzes container images and running containers to identify vulnerabilities, misconfigurations, and security threats before deployment. This proactive approach prevents potential breaches while maintaining development velocity.
Modern containerized environments create unique security challenges that traditional tools can't address, with one report indicating that 67% of organizations have delayed application deployment due to container security concerns. Containers bundle application code with dependencies, creating new attack vectors that require specialized detection methods. Integrating scanning into CI/CD pipelines ensures vulnerabilities are caught early without slowing development cycl
Wiz
Generative AI Security: Risks & Best Practices | Wiz
blogs_wiz·2025-10-12·CVSS 9.0
[CRITICAL] Generative AI Security: Risks & Best Practices | Wiz
## What is generative AI security?
Generative AI security protects organizations from unique risks created by AI systems that generate content, code, or data. This specialized cybersecurity discipline addresses threats like prompt injection, model theft, and data poisoning that traditional security tools can't detect. Organizations implement GenAI security through technical controls, governance policies, and specialized AI security platforms.
Generative AI creates new content from training data—text, images, code, or videos. Popular examples include ChatGPT for text generation and DALL-E for image creation. These systems introduce security challenges because they process sensitive data and can be manipulated to produce harmful outputs.
GenAI offers massive productivity gains, but only w
Wiz
Generative AI Security: Risks & Best Practices | Wiz
blogs_wiz·2025-10-12·CVSS 9.0
[CRITICAL] Generative AI Security: Risks & Best Practices | Wiz
## What is generative AI security?
Generative AI security protects organizations from unique risks created by AI systems that generate content, code, or data. This specialized cybersecurity discipline addresses threats like prompt injection, model theft, and data poisoning that traditional security tools can't detect. Organizations implement GenAI security through technical controls, governance policies, and specialized AI security platforms.
Generative AI creates new content from training data—text, images, code, or videos. Popular examples include ChatGPT for text generation and DALL-E for image creation. These systems introduce security challenges because they process sensitive data and can be manipulated to produce harmful outputs.
GenAI offers massive productivity gains, but only w
Wiz
Generative AI Security: Risks & Best Practices | Wiz
blogs_wiz·2025-10-12·CVSS 9.0
[CRITICAL] Generative AI Security: Risks & Best Practices | Wiz
## What is generative AI security?
Generative AI security protects organizations from unique risks created by AI systems that generate content, code, or data. This specialized cybersecurity discipline addresses threats like prompt injection, model theft, and data poisoning that traditional security tools can't detect. Organizations implement GenAI security through technical controls, governance policies, and specialized AI security platforms.
Generative AI creates new content from training data—text, images, code, or videos. Popular examples include ChatGPT for text generation and DALL-E for image creation. These systems introduce security challenges because they process sensitive data and can be manipulated to produce harmful outputs.
GenAI offers massive productivity gains, but only w
Wiz
Generative AI Security: Risks & Best Practices | Wiz
blogs_wiz·2025-10-12·CVSS 9.0
[CRITICAL] Generative AI Security: Risks & Best Practices | Wiz
## What is generative AI security?
Generative AI security protects organizations from unique risks created by AI systems that generate content, code, or data. This specialized cybersecurity discipline addresses threats like prompt injection, model theft, and data poisoning that traditional security tools can't detect. Organizations implement GenAI security through technical controls, governance policies, and specialized AI security platforms.
Generative AI creates new content from training data—text, images, code, or videos. Popular examples include ChatGPT for text generation and DALL-E for image creation. These systems introduce security challenges because they process sensitive data and can be manipulated to produce harmful outputs.
GenAI offers massive productivity gains, but only w
Wiz
Generative AI Security: Risks & Best Practices | Wiz
blogs_wiz·2025-10-12·CVSS 9.0
[CRITICAL] Generative AI Security: Risks & Best Practices | Wiz
## What is generative AI security?
Generative AI security protects organizations from unique risks created by AI systems that generate content, code, or data. This specialized cybersecurity discipline addresses threats like prompt injection, model theft, and data poisoning that traditional security tools can't detect. Organizations implement GenAI security through technical controls, governance policies, and specialized AI security platforms.
Generative AI creates new content from training data—text, images, code, or videos. Popular examples include ChatGPT for text generation and DALL-E for image creation. These systems introduce security challenges because they process sensitive data and can be manipulated to produce harmful outputs.
GenAI offers massive productivity gains, but only w
Wiz
Generative AI Security: Risks & Best Practices | Wiz
blogs_wiz·2025-10-12·CVSS 9.0
[CRITICAL] Generative AI Security: Risks & Best Practices | Wiz
## What is generative AI security?
Generative AI security protects organizations from unique risks created by AI systems that generate content, code, or data. This specialized cybersecurity discipline addresses threats like prompt injection, model theft, and data poisoning that traditional security tools can't detect. Organizations implement GenAI security through technical controls, governance policies, and specialized AI security platforms.
Generative AI creates new content from training data—text, images, code, or videos. Popular examples include ChatGPT for text generation and DALL-E for image creation. These systems introduce security challenges because they process sensitive data and can be manipulated to produce harmful outputs.
GenAI offers massive productivity gains, but only w
Wiz
Generative AI Security: Risks & Best Practices | Wiz
blogs_wiz·2025-10-12·CVSS 9.0
[CRITICAL] Generative AI Security: Risks & Best Practices | Wiz
## What is generative AI security?
Generative AI security protects organizations from unique risks created by AI systems that generate content, code, or data. This specialized cybersecurity discipline addresses threats like prompt injection, model theft, and data poisoning that traditional security tools can't detect. Organizations implement GenAI security through technical controls, governance policies, and specialized AI security platforms.
Generative AI creates new content from training data—text, images, code, or videos. Popular examples include ChatGPT for text generation and DALL-E for image creation. These systems introduce security challenges because they process sensitive data and can be manipulated to produce harmful outputs.
GenAI offers massive productivity gains, but only w
Wiz
Sécurité de l’IA générative : risques et bonnes pratiques | Wiz
blogs_wiz·2025-10-12
Sécurité de l’IA générative : risques et bonnes pratiques | Wiz
## Qu'est-ce que la sécurité de l'IA générative ?
La sécurité de l'IA générative protège les organisations des risques uniques créés par les systèmes d'IA qui génèrent du contenu, du code ou des données. Cette discipline spécialisée de cybersécurité traite des menaces comme l'injection de prompt, le vol de modèles et l'empoisonnement de données que les outils de sécurité traditionnels ne peuvent pas détecter. Les organisations implémentent la sécurité de l'IA générative via des contrôles techniques, des politiques de gouvernance et des plateformes de sécurité IA spécialisées.
L'IA générative crée du nouveau contenu à partir de données d'entraînement : texte, images, code ou vidéos. Les exemples populaires incluent ChatGPT pour la génération de texte et DALL-E pour la création d'images. C
Wiz
Generative AI Security: Risks & Best Practices | Wiz
blogs_wiz·2025-10-12·CVSS 9.0
[CRITICAL] Generative AI Security: Risks & Best Practices | Wiz
## What is generative AI security?
Generative AI security protects organizations from unique risks created by AI systems that generate content, code, or data. This specialized cybersecurity discipline addresses threats like prompt injection, model theft, and data poisoning that traditional security tools can't detect. Organizations implement GenAI security through technical controls, governance policies, and specialized AI security platforms.
Generative AI creates new content from training data—text, images, code, or videos. Popular examples include ChatGPT for text generation and DALL-E for image creation. These systems introduce security challenges because they process sensitive data and can be manipulated to produce harmful outputs.
GenAI offers massive productivity gains, but only w
Wiz
Generative AI Security: Risks & Best Practices | Wiz
blogs_wiz·2025-10-12·CVSS 9.0
[CRITICAL] Generative AI Security: Risks & Best Practices | Wiz
## What is generative AI security?
Generative AI security protects organizations from unique risks created by AI systems that generate content, code, or data. This specialized cybersecurity discipline addresses threats like prompt injection, model theft, and data poisoning that traditional security tools can't detect. Organizations implement GenAI security through technical controls, governance policies, and specialized AI security platforms.
Generative AI creates new content from training data—text, images, code, or videos. Popular examples include ChatGPT for text generation and DALL-E for image creation. These systems introduce security challenges because they process sensitive data and can be manipulated to produce harmful outputs.
GenAI offers massive productivity gains, but only w
Wiz
Generative AI Security: Risks & Best Practices | Wiz
blogs_wiz·2025-10-12·CVSS 9.0
[CRITICAL] Generative AI Security: Risks & Best Practices | Wiz
## What is generative AI security?
Generative AI security protects organizations from unique risks created by AI systems that generate content, code, or data. This specialized cybersecurity discipline addresses threats like prompt injection, model theft, and data poisoning that traditional security tools can't detect. Organizations implement GenAI security through technical controls, governance policies, and specialized AI security platforms.
Generative AI creates new content from training data—text, images, code, or videos. Popular examples include ChatGPT for text generation and DALL-E for image creation. These systems introduce security challenges because they process sensitive data and can be manipulated to produce harmful outputs.
GenAI offers massive productivity gains, but only w
Wiz
Sécurité de l’IA générative : risques et bonnes pratiques | Wiz
blogs_wiz·2025-10-12
Sécurité de l’IA générative : risques et bonnes pratiques | Wiz
## Qu'est-ce que la sécurité de l'IA générative ?
La sécurité de l'IA générative protège les organisations des risques uniques créés par les systèmes d'IA qui génèrent du contenu, du code ou des données. Cette discipline spécialisée de cybersécurité traite des menaces comme l'injection de prompt, le vol de modèles et l'empoisonnement de données que les outils de sécurité traditionnels ne peuvent pas détecter. Les organisations implémentent la sécurité de l'IA générative via des contrôles techniques, des politiques de gouvernance et des plateformes de sécurité IA spécialisées.
L'IA générative crée du nouveau contenu à partir de données d'entraînement : texte, images, code ou vidéos. Les exemples populaires incluent ChatGPT pour la génération de texte et DALL-E pour la création d'images. C
Wiz
Generative AI Security: Risks & Best Practices | Wiz
blogs_wiz·2025-10-12·CVSS 9.0
[CRITICAL] Generative AI Security: Risks & Best Practices | Wiz
## What is generative AI security?
Generative AI security protects organizations from unique risks created by AI systems that generate content, code, or data. This specialized cybersecurity discipline addresses threats like prompt injection, model theft, and data poisoning that traditional security tools can't detect. Organizations implement GenAI security through technical controls, governance policies, and specialized AI security platforms.
Generative AI creates new content from training data—text, images, code, or videos. Popular examples include ChatGPT for text generation and DALL-E for image creation. These systems introduce security challenges because they process sensitive data and can be manipulated to produce harmful outputs.
GenAI offers massive productivity gains, but only w
Wiz
Generative AI Security: Risks & Best Practices | Wiz
blogs_wiz·2025-10-12·CVSS 9.0
[CRITICAL] Generative AI Security: Risks & Best Practices | Wiz
## What is generative AI security?
Generative AI security protects organizations from unique risks created by AI systems that generate content, code, or data. This specialized cybersecurity discipline addresses threats like prompt injection, model theft, and data poisoning that traditional security tools can't detect. Organizations implement GenAI security through technical controls, governance policies, and specialized AI security platforms.
Generative AI creates new content from training data—text, images, code, or videos. Popular examples include ChatGPT for text generation and DALL-E for image creation. These systems introduce security challenges because they process sensitive data and can be manipulated to produce harmful outputs.
GenAI offers massive productivity gains, but only w
Wiz
Generative AI Security: Risks & Best Practices | Wiz
blogs_wiz·2025-10-12·CVSS 9.0
[CRITICAL] Generative AI Security: Risks & Best Practices | Wiz
## What is generative AI security?
Generative AI security protects organizations from unique risks created by AI systems that generate content, code, or data. This specialized cybersecurity discipline addresses threats like prompt injection, model theft, and data poisoning that traditional security tools can't detect. Organizations implement GenAI security through technical controls, governance policies, and specialized AI security platforms.
Generative AI creates new content from training data—text, images, code, or videos. Popular examples include ChatGPT for text generation and DALL-E for image creation. These systems introduce security challenges because they process sensitive data and can be manipulated to produce harmful outputs.
GenAI offers massive productivity gains, but only w
Wiz
Generative AI Security: Risks & Best Practices | Wiz
blogs_wiz·2025-10-12·CVSS 9.0
[CRITICAL] Generative AI Security: Risks & Best Practices | Wiz
## What is generative AI security?
Generative AI security protects organizations from unique risks created by AI systems that generate content, code, or data. This specialized cybersecurity discipline addresses threats like prompt injection, model theft, and data poisoning that traditional security tools can't detect. Organizations implement GenAI security through technical controls, governance policies, and specialized AI security platforms.
Generative AI creates new content from training data—text, images, code, or videos. Popular examples include ChatGPT for text generation and DALL-E for image creation. These systems introduce security challenges because they process sensitive data and can be manipulated to produce harmful outputs.
GenAI offers massive productivity gains, but only w
Wiz
NVIDIAScape - NVIDIA AI Vulnerability (CVE-2025-23266) | Wiz Blog
blogs_wiz·2025-07-17·CVSS 9.0
CVE-2025-23266 [CRITICAL] NVIDIAScape - NVIDIA AI Vulnerability (CVE-2025-23266) | Wiz Blog
## Executive Summary
Wiz Research discovered a critical container escape vulnerability in the NVIDIA Container Toolkit (NCT), which we've dubbed #NVIDIAScape . This toolkit powers many AI services offered by cloud and SaaS providers, and the vulnerability, now tracked as CVE-2025-23266 , has been assigned a CVSS score of 9.0 (Critical) . It allows a malicious container to bypass isolation measures and gain full root access to the host machine. This flaw stems from a subtle misconfiguration in how the toolkit handles OCI hooks, and it can be exploited with a stunningly simple three-line Dockerfile.
Because the NVIDIA Container Toolkit is the backbone for many managed AI and GPU services across all major cloud providers, this vulnerability represents a systemic risk to the AI ecosystem, po
Wiz
NVIDIAScape - NVIDIA AI Vulnerability (CVE-2025-23266) | Wiz Blog
blogs_wiz·2025-07-17·CVSS 9.0
CVE-2025-23266 [CRITICAL] NVIDIAScape - NVIDIA AI Vulnerability (CVE-2025-23266) | Wiz Blog
# Executive Summary
Wiz Research discovered a critical container escape vulnerability in the NVIDIA Container Toolkit (NCT), which we've dubbed #NVIDIAScape. This toolkit powers many AI services offered by cloud and SaaS providers, and the vulnerability, now tracked as CVE-2025-23266, has been assigned a CVSS score of 9.0 (Critical). It allows a malicious container to bypass isolation measures and gain full root access to the host machine. This flaw stems from a subtle misconfiguration in how the toolkit handles OCI hooks, and it can be exploited with a stunningly simple three-line Dockerfile.
Because the NVIDIA Container Toolkit is the backbone for many managed AI and GPU services across all major cloud providers, this vulnerability represents a systemic risk to the AI ecosystem, potent
Trendmicro
Incomplete NVIDIA Patch to CVE-2024-0132 Exposes AI Infrastructure and Data to Critical Risks
blogs_trendmicro·2025-04-10·CVSS 9.0
CVE-2024-0132 [CRITICAL] Incomplete NVIDIA Patch to CVE-2024-0132 Exposes AI Infrastructure and Data to Critical Risks
Exploits y vulnerabilidades
## Incomplete NVIDIA Patch to CVE-2024-0132 Exposes AI Infrastructure and Data to Critical Risks
A previously disclosed vulnerability in NVIDIA Container Toolkit has an incomplete patch, which, if exploited, could put a wide range of AI infrastructure and sensitive data at risk.
By: Abdelrahman Esmail Apr 10, 2025 Read time: ( words)
Save to Folio
The Docker API as a privileged interface. Consequently, any user with API access effectively holds root-level privileges on the host. It remains unclear whether this issue originates from Docker’s runtime or the Linux’s kernel handling of mount entries.
Rapid patching remains the most effective mitigation, but it might not always be feasible especially in complex or critical production environments. Trend Vision
Trendmicro
Incomplete NVIDIA Patch to CVE-2024-0132 Exposes AI Infrastructure and Data to Critical Risks
blogs_trendmicro·2025-04-10·CVSS 9.0
CVE-2024-0132 [CRITICAL] Incomplete NVIDIA Patch to CVE-2024-0132 Exposes AI Infrastructure and Data to Critical Risks
Ausnutzung von Schwachstellen
## Incomplete NVIDIA Patch to CVE-2024-0132 Exposes AI Infrastructure and Data to Critical Risks
A previously disclosed vulnerability in NVIDIA Container Toolkit has an incomplete patch, which, if exploited, could put a wide range of AI infrastructure and sensitive data at risk.
By: Abdelrahman Esmail Apr 10, 2025 Read time: ( words)
Save to Folio
The Docker API as a privileged interface. Consequently, any user with API access effectively holds root-level privileges on the host. It remains unclear whether this issue originates from Docker’s runtime or the Linux’s kernel handling of mount entries.
Rapid patching remains the most effective mitigation, but it might not always be feasible especially in complex or critical production environments. Trend Visio
Trendmicro
Incomplete NVIDIA Patch to CVE-2024-0132 Exposes AI Infrastructure and Data to Critical Risks
blogs_trendmicro·2025-04-10·CVSS 9.0
CVE-2024-0132 [CRITICAL] Incomplete NVIDIA Patch to CVE-2024-0132 Exposes AI Infrastructure and Data to Critical Risks
Exploits & Vulnerabilities
## Incomplete NVIDIA Patch to CVE-2024-0132 Exposes AI Infrastructure and Data to Critical Risks
A previously disclosed vulnerability in NVIDIA Container Toolkit has an incomplete patch, which, if exploited, could put a wide range of AI infrastructure and sensitive data at risk.
By: Abdelrahman Esmail Apr 10, 2025 Read time: ( words)
Save to Folio
The Docker API as a privileged interface. Consequently, any user with API access effectively holds root-level privileges on the host. It remains unclear whether this issue originates from Docker’s runtime or the Linux’s kernel handling of mount entries.
Rapid patching remains the most effective mitigation, but it might not always be feasible especially in complex or critical production environments. Trend Vision O
Trendmicro
Incomplete NVIDIA Patch to CVE-2024-0132 Exposes AI Infrastructure and Data to Critical Risks
blogs_trendmicro·2025-04-10·CVSS 9.0
CVE-2024-0132 [CRITICAL] Incomplete NVIDIA Patch to CVE-2024-0132 Exposes AI Infrastructure and Data to Critical Risks
Exploits & Vulnerabilities
# Incomplete NVIDIA Patch to CVE-2024-0132 Exposes AI Infrastructure and Data to Critical Risks
A previously disclosed vulnerability in NVIDIA Container Toolkit has an incomplete patch, which, if exploited, could put a wide range of AI infrastructure and sensitive data at risk.
By: Abdelrahman Esmail
2025/04/10
Read time: ( words)
Save to Folio
Summary:
- Trend Research identified that NVIDIA’s September 2024 security update for a critical vulnerability (CVE-2024-0132) in the NVIDIA Container Toolkit was incomplete, leaving systems potentially vulnerable to container escape attacks. Additionally, researchers discovered a denial-of-service (DoS) vulnerability affecting Docker on Linux.
- Exploiting these vulnerabilities could enable attackers to access sens
Trendmicro
Incomplete NVIDIA Patch to CVE-2024-0132 Exposes AI Infrastructure and Data to Critical Risks
blogs_trendmicro·2025-04-10·CVSS 9.0
CVE-2024-0132 [CRITICAL] Incomplete NVIDIA Patch to CVE-2024-0132 Exposes AI Infrastructure and Data to Critical Risks
Exploits & Vulnerabilities
## Incomplete NVIDIA Patch to CVE-2024-0132 Exposes AI Infrastructure and Data to Critical Risks
A previously disclosed vulnerability in NVIDIA Container Toolkit has an incomplete patch, which, if exploited, could put a wide range of AI infrastructure and sensitive data at risk.
By: Abdelrahman Esmail 2025/04/10 Read time: ( words)
Save to Folio
The Docker API as a privileged interface. Consequently, any user with API access effectively holds root-level privileges on the host. It remains unclear whether this issue originates from Docker’s runtime or the Linux’s kernel handling of mount entries.
Rapid patching remains the most effective mitigation, but it might not always be feasible especially in complex or critical production environments. Trend Vision One
Wiz
Key Takeaways from the 2025 State of AI in the Cloud Report | Wiz Blog
blogs_wiz·2025-03-07
Key Takeaways from the 2025 State of AI in the Cloud Report | Wiz Blog
AI adoption continues to surge across cloud environments, driving innovation but also introducing new security challenges. In our second annual State of AI in the Cloud report, the Wiz Research team analyzed aggregated data from over 150,000 cloud accounts to explore the evolving AI landscape. This year’s findings highlight the rapid growth of self-hosted AI models, the rise of DeepSeek, and the persistent need for stronger security measures. Here’s what you need to know:
# AI Adoption Remains Strong, with Self-Hosted Models on the Rise
Organizations continue to embrace AI in their cloud environments, with 74% now using managed AI services—up from 70% last year – and 85% hosting some sort of AI tech. However, the real shift is happening in self-hosted AI models, where adoption has skyroc
Wiz
Key Takeaways from the 2025 State of AI in the Cloud Report | Wiz Blog
blogs_wiz·2025-03-07
Key Takeaways from the 2025 State of AI in the Cloud Report | Wiz Blog
AI adoption continues to surge across cloud environments, driving innovation but also introducing new security challenges. In our second annual State of AI in the Cloud report, the Wiz Research team analyzed aggregated data from over 150,000 cloud accounts to explore the evolving AI landscape. This year’s findings highlight the rapid growth of self-hosted AI models, the rise of DeepSeek, and the persistent need for stronger security measures. Here’s what you need to know:
## AI Adoption Remains Strong, with Self-Hosted Models on the Rise
Organizations continue to embrace AI in their cloud environments, with 74% now using managed AI services—up from 70% last year – and 85% hosting some sort of AI tech. However, the real shift is happening in self-hosted AI models, where adoption has skyro
Wiz
NVIDIA AI vulnerability: Deep Dive into CVE 2024-0132 | Wiz Blog
blogs_wiz·2025-02-11·CVSS 9.0
CVE-2024-0132 [CRITICAL] NVIDIA AI vulnerability: Deep Dive into CVE 2024-0132 | Wiz Blog
# Executive summary
In September of last year, Wiz Research uncovered a critical security vulnerability, tracked as CVE-2024-0132, in the widely used NVIDIA Container Toolkit, which provides containerized AI applications with access to GPU resources. Our initial blog post was purposely vague because the vulnerability was under embargo for an extended period, allowing both NVIDIA and cloud providers to address the issue. As we detailed in our initial blog post, this vulnerability affects any AI application—whether in the cloud or on-premises—that is running the vulnerable container toolkit. Today, we are ready to release the technical details of the vulnerability.
The vulnerability enables attackers who control a container image executed by the vulnerable toolkit to escape from the contai
Wiz
Posts by Andres Riancho | Wiz
blogs_wiz·2025-02-11·CVSS 9.0
CVE-2024-0132 [CRITICAL] Posts by Andres Riancho | Wiz
## How Wiz found a Critical NVIDIA AI vulnerability: Deep Dive into a container escape (CVE-2024-0132)
Technical details on a critical severity vulnerability (CVE-2024-0132) in NVIDIA Container Toolkit and GPU Operator, affecting cloud service providers .
Wiz
NVIDIA AI vulnerability: Deep Dive into CVE 2024-0132 | Wiz Blog
blogs_wiz·2025-02-11·CVSS 9.0
CVE-2024-0132 [CRITICAL] NVIDIA AI vulnerability: Deep Dive into CVE 2024-0132 | Wiz Blog
## Executive summary
In September of last year, Wiz Research uncovered a critical security vulnerability, tracked as CVE-2024-0132, in the widely used NVIDIA Container Toolkit, which provides containerized AI applications with access to GPU resources. Our initial blog post was purposely vague because the vulnerability was under embargo for an extended period, allowing both NVIDIA and cloud providers to address the issue. As we detailed in our initial blog post, this vulnerability affects any AI application—whether in the cloud or on-premises—that is running the vulnerable container toolkit. Today, we are ready to release the technical details of the vulnerability.
The vulnerability enables attackers who control a container image executed by the vulnerable toolkit to escape from the conta
Wiz
Reddit AMA Recap: Containers Security | Wiz Blog
blogs_wiz·2025-02-10
Reddit AMA Recap: Containers Security | Wiz Blog
Last week, we hopped on the /cybersecurity subreddit for a container security AMA and wow, what great questions from the community! We talked Kubernetes, cloud misconfigurations, AI, and IAM. It was clear that as more and more workloads move to Kubernetes and cloud, security practitioners must evolve their approach and rethink how they secure these ephemeral, decentralized environments in a variety of ways.
Here’s a recap of the best questions, hottest takes, and key points from the AMA. You can view the full discussion on Reddit.
# What is the biggest container security challenge?
Our answer: having 100% container image security coverage. Container images often contain vulnerabilities inherited from third-party dependencies, so teams must ensure that only trusted, verified images are d
Wiz
Reddit AMA Recap: Containers Security | Wiz Blog
blogs_wiz·2025-02-10
Reddit AMA Recap: Containers Security | Wiz Blog
Last week, we hopped on the /cybersecurity subreddit for a container security AMA and wow, what great questions from the community! We talked Kubernetes, cloud misconfigurations, AI, and IAM. It was clear that as more and more workloads move to Kubernetes and cloud, security practitioners must evolve their approach and rethink how they secure these ephemeral, decentralized environments in a variety of ways.
Here’s a recap of the best questions, hottest takes, and key points from the AMA. You can view the full discussion on Reddit .
## What is the biggest container security challenge?
Our answer: having 100% container image security coverage. Container images often contain vulnerabilities inherited from third-party dependencies, so teams must ensure that only trusted, verified images are
Wiz
Crying Out Cloud - October 2024 Newsletter | Wiz
blogs_wiz·2024-10-01·CVSS 9.0
CVE-2024-0132 [CRITICAL] Crying Out Cloud - October 2024 Newsletter | Wiz
Welcome back! In this edition, we bring you the latest in cloud security – noteworthy incidents, exclusive data, and crucial vulnerabilities. Let's dive in.
Here are our top picks!
## 🔍 Highlights
Critical Vulnerability in NVIDIA Container Toolkit
Wiz Research uncovered a critical vulnerability, CVE-2024-0132, in the widely used NVIDIA Container Toolkit. The vulnerability allows attackers with control over a container image to escape the container and gain full access to the underlying host. It is strongly recommended to update the affected package to the latest version 1.16.2, while focusing on container hosts that might run untrusted container images.
According to Wiz data, 33% of cloud environments are impacted by CVE-2024-0132.
Learn more in our blog .
## 🐞 High Profile Vulnerab
Checkpoint
30th September – Threat Intelligence Report
blogs_checkpoint·2024-09-30
CVE-2024-0132 30th September – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 30th September – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 30th September, please download our Threat Intelligence Bulletin .
TOP ATTACKS AND BREACHES
American money transfer service MoneyGram has experienced a cyber-attack which led to significant network outages that disrupted its services globally. The attack has affected money transactions, particularly in the Caribbean, Jamaica and Mexico. No threat actor has claimed responsibility yet.
The Centers for Medicar
Bleepingcomputer
Critical flaw in NVIDIA Container Toolkit allows full host takeover
blogs_bleepingcomputer·2024-09-29·CVSS 9.0
CVE-2024-0132 [CRITICAL] Critical flaw in NVIDIA Container Toolkit allows full host takeover
## Critical flaw in NVIDIA Container Toolkit allows full host takeover
## Bill Toulas
## Container escape flaw
The security issue CVE-2024-0132 received a critical-severity score of 9.0. It is a container escape problem that affects NVIDIA Container Toolkit 1.16.1 and earlier, and GPU Operator 24.6.1 and older.
The problem is a lack of secure isolation of the containerized GPU from the host, allowing containers to mount sensitive parts of the host filesystem or access runtime resources like Unix sockets for inter-process communication.
While most filesystems are mounted with “read-only” permissions, certain Unix sockets such as ‘docker.sock’ and ‘containerd.sock’ remain writable, allowing direct interactions with the host, including command execution.
An attacker can take advantage o
Trendmicro
Trend Detects NVIDIA AI Toolkit Vulnerability
blogs_trendmicro·2024-09-27·CVSS 9.0
[CRITICAL] Trend Detects NVIDIA AI Toolkit Vulnerability
Artificial Intelligence (AI)
# Trend Detects NVIDIA AI Toolkit Vulnerability
On Wednesday, NVIDIA released updates to fix a critical vulnerability in its NVIDIA Container Toolkit, which, if exploited, could put a wide range of AI infrastructure and underlying data/secrets at risk.
By: Trend Micro
2024/09/27
Read time: ( words)
Save to Folio
On Wednesday, NVIDIA released updates to fix a critical vulnerability in its NVIDIA Container Toolkit, which, if exploited, could put a wide range of AI infrastructure and underlying data/secrets at risk. With a CVSS v3.1 rating of 9.0, the flaw should be patched immediately. But for organizations unable to do so, Trend Vision One™ will provide proactive protection against attacks attempting to exploit it.
## What is the vulnerability?
The NVIDI
Wiz
Wiz Research Finds Critical NVIDIA AI Vulnerability Affecting Containers Using NVIDIA GPUs, Including Over 35% of Cloud Environments | Wiz Blog
blogs_wiz·2024-09-26·CVSS 9.0
CVE-2024-0132 [CRITICAL] Wiz Research Finds Critical NVIDIA AI Vulnerability Affecting Containers Using NVIDIA GPUs, Including Over 35% of Cloud Environments | Wiz Blog
# Executive summary
Wiz Research has uncovered a critical security vulnerability, CVE-2024-0132, in the widely used NVIDIA Container Toolkit, which provides containerized AI applications with access to GPU resources. This impacts any AI application – in the cloud or on-premise – that is running the vulnerable container toolkit to enable GPU support.
The vulnerability enables attackers who control a container image executed by the vulnerable toolkit to escape from that container and gain full access to the underlying host system, posing a serious risk to sensitive data and infrastructure.
On September 26, NVIDIA released a security bulletin along with a patched version of the affected product. Thank you to the entire NVIDIA team that worked with us throughout the disclosure process. We g
Wiz
Wiz Research Finds Critical NVIDIA AI Vulnerability Affecting Containers Using NVIDIA GPUs, Including Over 35% of Cloud Environments | Wiz Blog
blogs_wiz·2024-09-26·CVSS 9.0
CVE-2024-0132 [CRITICAL] Wiz Research Finds Critical NVIDIA AI Vulnerability Affecting Containers Using NVIDIA GPUs, Including Over 35% of Cloud Environments | Wiz Blog
## Executive summary
Wiz Research has uncovered a critical security vulnerability, CVE-2024-0132, in the widely used NVIDIA Container Toolkit, which provides containerized AI applications with access to GPU resources. This impacts any AI application – in the cloud or on-premise – that is running the vulnerable container toolkit to enable GPU support.
The vulnerability enables attackers who control a container image executed by the vulnerable toolkit to escape from that container and gain full access to the underlying host system, posing a serious risk to sensitive data and infrastructure.
On September 26, NVIDIA released a security bulletin along with a patched version of the affected product. Thank you to the entire NVIDIA team that worked with us throughout the disclosure process. We
arXiv
LegionITS: A Federated Intrusion-Tolerant System Architecture
arxiv_fulltext·2025-12-16
LegionITS: A Federated Intrusion-Tolerant System Architecture
legion
T. Freitas et al.
[1]Tadeu Freitas[orcid=0000-0001-5573-2434]
[email protected] [1]
[1]Carlos Novo[orcid=0009-0003-0094-5565]
[email protected]
[1,2]Manuel E. Correia[orcid=T0000-0002-2348-8075]
[email protected]
[1,3]Rolando Martins[orcid=0000-0002-1838-1417]
[email protected]
[1]Corresponding author
[1]
organization=Departamento de Ciências de Computadores, Faculdade de Ci\^encias, Universidade do Porto,
postcode=Porto,
country=Portugal
[2]
organization=CRACS - INESC TEC,
postcode=Porto,
country=Portugal
[3]
organization=Safehelm,
postcode=Porto,
country=Portugal
[mode = title]legion: A Federated Intrusion-Tolerant System Architecture
## Abstract
The growing sophistication, frequency, and diversity of cyberattacks increasingly exceed the capacity of individual en
2024-09-26
Published