<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Nvidia on CuraSec</title><link>https://curasec.metacog.co.kr/tags/nvidia/</link><description>Recent content in Nvidia on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 26 Aug 2026 11:42:13 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/nvidia/index.xml" rel="self" type="application/rss+xml"/><item><title>NVIDIA NemoClaw flaw lets malicious webpage hijack local Ollama AI agent</title><link>https://curasec.metacog.co.kr/insights/2026-08-26-a-malicious-webpage-could-poison-your-local-ai-model-behind/</link><pubDate>Wed, 26 Aug 2026 11:42:13 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-26-a-malicious-webpage-could-poison-your-local-ai-model-behind/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> If you run Ollama locally or in AI agent pipelines alongside NemoClaw, this unauthenticated takeover path (likely DNS rebinding or CORS abuse against Ollama&amp;rsquo;s HTTP API) is a real exposure. Check Ollama&amp;rsquo;s network binding config now and watch for NVIDIA&amp;rsquo;s patch or mitigation advisory — no public PoC or KEV listing yet, but the attack surface is credible.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> No IOCs, no active exploitation, and no mapped TTPs — nothing to hunt or detect today. However, the technique (webpage-initiated control of a local AI agent instance to inject hidden instructions) is a novel attack class worth tracking as AI agent deployments grow in enterprise environments.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> No breach or regulatory trigger here, but the finding illustrates that local AI agent tooling carries real attack surface — useful input for AI security policy and vendor risk reviews if your organization is adopting agentic AI infrastructure.&lt;/li>
&lt;/ul></description></item></channel></rss>