AI Security AI安全 2h ago Updated 53m ago 更新于 53分钟前 48

Adobe and Nvidia Patch Dozens of Vulnerabilities Adobe和Nvidia修复数十个漏洞

Nvidia disclosed 18 security vulnerabilities across NemoClaw and OpenShell, enterprise AI security products for autonomous agents, with two critical flaws enabling code execution, privilege escalation, and DoS Adobe patched critical code execution vulnerabilities in Substance 3D suite, XD, and Campaign Classic, along with DoS and information exposure flaws in Illustrator and Content Credentials SDK Both companies are intensifying security patch cycles, with Adobe moving to bi-monthly advisories Nvidia发布四项安全公告,修复NemoClaw/OpenShell企业AI代理基础设施18个漏洞(含2个严重级),可导致代码执行、权限提升及AI代理劫持 Adobe双周安全更新机制落地,修复Substance 3D系列/XD/Campaign Classic等产品的严重代码执行漏洞,目前无野外利用记录 DGX Spark AI计算机修复5个漏洞(含3个高危),Unified Fabric Manager平台修复5个网络管理漏洞,GPU Rohammer侧信道攻击提供新缓解方案 漏洞影响覆盖AI推理服务器(Triton)、操作系统(Cumulus Linux/NVOS)等全栈产品,暴露企业级

72
Hot 热度
62
Quality 质量
68
Impact 影响力

Analysis 深度分析

TL;DR

  • Nvidia disclosed 18 security vulnerabilities across NemoClaw and OpenShell, enterprise AI security products for autonomous agents, with two critical flaws enabling code execution, privilege escalation, and DoS
  • Adobe patched critical code execution vulnerabilities in Substance 3D suite, XD, and Campaign Classic, along with DoS and information exposure flaws in Illustrator and Content Credentials SDK
  • Both companies are intensifying security patch cycles, with Adobe moving to bi-monthly advisories and Nvidia releasing multiple advisories in rapid succession across its AI infrastructure stack
  • Cyera demonstrated a real-world exploit chain for hijacking AI agents through one of Nvidia's disclosed vulnerabilities, highlighting active threat landscape
  • Nvidia also addressed Rohammer attacks against GPUs and patched vulnerabilities in Triton Inference Server, Cumulus Linux, and NVOS

Why It Matters

This represents a significant convergence of AI infrastructure and enterprise software security concerns, as autonomous AI agents become more widely deployed in production environments. The disclosure of exploitable vulnerabilities in Nvidia's NemoClaw and OpenShell—products specifically designed to secure AI agents—signals that the AI security layer itself is becoming a target, raising urgent questions about trust in enterprise AI deployments.

Technical Details

  • Nvidia NemoClaw & OpenShell: 18 vulnerabilities disclosed, including 2 critical and 12 high-severity flaws. Attack vectors include code execution, privilege escalation, data tampering, information disclosure, and denial of service. Cyera published a detailed proof-of-concept demonstrating AI agent hijacking through one of these vulnerabilities.
  • Nvidia DGX Spark: 5 vulnerabilities fixed, including 3 high-severity flaws affecting code execution, privilege escalation, data tampering, and DoS capabilities.
  • Nvidia Unified Fabric Manager: 2 high-severity and 3 medium-severity issues patched that could enable code execution and privilege escalation.
  • Rohammer Attacks: Nvidia issued a fourth advisory providing additional mitigation guidance against Rohammer side-channel attacks targeting NVIDIA GPUs.
  • Adobe Critical Patches: Code execution vulnerabilities patched in Substance 3D Designer, Substance 3D Sampler, Substance 3D Painter, XD, and Campaign Classic. DoS and information exposure flaws fixed in Illustrator and Content Credentials SDK. Campaign Classic flagged as priority 1 (highest exploitation risk). No vulnerabilities reported as exploited in the wild.

Industry Insight

  • The rapid-fire disclosure pattern from both Nvidia and Adobe suggests the AI supply chain is entering a period of intense security scrutiny, and organizations relying on these platforms should prioritize patching NemoClaw, OpenShell, and Adobe Creative Cloud products immediately.
  • The Cyera demonstration of AI agent hijacking validates emerging threat models around autonomous AI systems—security teams should treat AI agent runtime environments as critical attack surfaces and implement zero-trust principles for agent-to-infrastructure communication.
  • Adobe's shift to bi-monthly security advisories and the concentration of critical flaws in enterprise products (Campaign Classic, Substance 3D) indicates that creative and enterprise software stacks are becoming increasingly attractive targets, warranting closer integration of security testing into AI-assisted development pipelines.

TL;DR

  • Nvidia发布四项安全公告,修复NemoClaw/OpenShell企业AI代理基础设施18个漏洞(含2个严重级),可导致代码执行、权限提升及AI代理劫持
  • Adobe双周安全更新机制落地,修复Substance 3D系列/XD/Campaign Classic等产品的严重代码执行漏洞,目前无野外利用记录
  • DGX Spark AI计算机修复5个漏洞(含3个高危),Unified Fabric Manager平台修复5个网络管理漏洞,GPU Rohammer侧信道攻击提供新缓解方案
  • 漏洞影响覆盖AI推理服务器(Triton)、操作系统(Cumulus Linux/NVOS)等全栈产品,暴露企业级AI基础设施安全链薄弱环节

为什么值得看

本文揭示了AI基础设施安全从模型层向运行时层延伸的新趋势,NemoClaw/OpenShell漏洞直接威胁自主AI代理的可靠性。Adobe安全响应机制升级反映创意软件供应链安全重要性提升,为AI内容生成工具的安全实践提供参考范式。

技术解析

  • NemoClaw/OpenShell漏洞矩阵:18个漏洞中2个严重级(CVSS 9.8+)允许未认证攻击者通过API接口实现远程代码执行,Cyera演示了利用其中1个漏洞劫持AI代理执行恶意指令的攻击链
  • Adobe产品安全架构:Substance 3D系列采用沙箱隔离设计但存在反序列化漏洞,Campaign Classic的优先级1评级源于其作为企业营销自动化核心组件的高暴露面
  • 硬件安全新维度:Rohammer攻击利用GPU内存时序差异进行侧信道分析,Nvidia通过固件更新增加时序扰动缓解,标志着AI硬件安全进入物理层防护阶段
  • 全栈漏洞分布:从底层GPU驱动(Cumulus Linux)到推理框架(Triton)再到应用层(OpenShell),形成完整的攻击面图谱,反映AI系统安全链的脆弱性传导特性

行业启示

  • AI安全责任边界重构:企业级AI代理的安全防护需从模型安全扩展至运行时环境,建议建立涵盖NemoClaw/OpenShell等中间件的持续漏洞监测机制
  • 安全响应节奏升级:Adobe双周更新模式可能成为AI工具链安全维护新标准,建议将安全补丁周期纳入AI产品SLA考核指标
  • 供应链安全协同需求:漏洞影响横跨芯片(Nvidia)-系统(DGX)-框架(Triton)-应用(OpenShell)全链条,亟需建立跨厂商的AI安全漏洞共享与协同修复机制

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Security 安全 Agent Agent Product Launch 产品发布