Nvidia releases update for "serious" vulnerability in AI technology stack

CN
4 hours ago

Nvidia, the technology company, has released a software update to patch vulnerabilities in its Triton server, which is used by clients for artificial intelligence models.

Cybersecurity company Wiz has classified these vulnerabilities as "critical" level, stating that if not patched in a timely manner, they could lead to AI models being taken over, data theft, and response manipulation.

Nir Ohfeld, the head of vulnerability research at Wiz, told Cointelegraph: "The Wiz research team discovered a series of vulnerabilities that, when combined, could allow attackers without prior access to completely control the AI server."

He stated: "The attack starts with a small vulnerability that causes the server to leak a small portion of secret internal data. The attacker can then use this data to deceive one of the server's legitimate functions, thereby gaining control over private system components. This initial foothold is all they need to escalate their privileges and achieve full server takeover."

Triton is an open-source inference software designed by Nvidia to optimize artificial intelligence models.

While the full scope of clients using Triton is unclear, several well-known companies have been cited as users of the software, including Microsoft, Amazon, Oracle, Siemens, and American Express. According to a 2021 press release, over 25,000 companies use Nvidia's AI technology stack.

A Nvidia spokesperson declined to comment, only mentioning the company's security announcement. The disclosed vulnerabilities have been assigned the identifiers CVE-2025-23319, CVE-2025-23320, and CVE-2025-23334.

Ohfeld told Cointelegraph: "The most important step is to update to the patched version of Nvidia Triton inference server (version 25.07 or later). This directly fixes the entire chain of vulnerabilities."

Ohfeld added that, as of now, "we have not seen evidence of these specific vulnerabilities being exploited in real-world environments. However, Nvidia Triton is a very popular and widely used platform for AI workloads."

Security vulnerabilities in 2025 hindered the development of emerging technologies, including the cryptocurrency sector, where exploits have led to the theft of digital assets worth billions of dollars.

According to blockchain security auditing firm Hacken, access flaws and smart contract vulnerabilities led to cryptocurrency exploit losses of $3.1 billion in the first half of 2025. This figure has already surpassed the total losses for the entire year of 2024.

Meanwhile, some experts claim that AI agents and quantum computing may pose new cyber threats.

Related: The bigger the stage, the bigger the scam? 5 eye-catching suspicious cryptocurrency projects

Original article: “Nvidia Releases ‘Critical’ Vulnerability Update for AI Technology Stack”

免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

OKX:注册即返20%,全网最高返佣,不薅白不薅!
Ad
Share To
APP

X

Telegram

Facebook

Reddit

CopyLink