University of Toronto researchers presented GPUBreach at Black Hat 2026 — a Rowhammer attack that escalates from an unprivileged CUDA kernel to a host root shell, bypassing IOMMU, threatening shared AI cloud GPU infrastructure.
University of Toronto researchers presented GPUBreach at Black Hat 2026 — a Rowhammer attack that escalates from an unprivileged CUDA kernel to a host root shell, bypassing IOMMU, threatening shared AI cloud GPU infrastructure.
Novee Security disclosed CVE-2026-54316 at Black Hat USA 2026: a zero-privilege GitHub issue can reach CI runner secrets across Claude Code, Gemini CLI, and OpenAI Codex. The Claude Code variant eventually exfiltrated secrets one character at a time via Hugging Face download counters. A separate Gemini CLI flaw scored CVSS 10.0.
Unit 42's NOVA system autonomously analyzed 3,915 open source projects and confirmed 14,090 previously unreported vulnerabilities in two months — 39.7% rated high or critical under CVSS 4.0. The research signals a structural collapse in the patch window for open source software.
Oligo Security presented at Black Hat USA 2026 this week: attackers have weaponised Ray, the open-source AI orchestration platform, into a self-propagating botnet with over 200,000 exposed servers. Compromised clusters autonomously scan for and infect new Ray deployments worldwide.
Researchers at Black Hat USA 2026 demonstrated CoreBreak, a class of vulnerabilities in AI agent frameworks where tool execution is triggered without a model turn — bypassing every model-layer guardrail. AWS, Google, and Vercel have all patched. An open-source AWS library exposure remains.