Wednesday, August 4, 2021

YAUZA CTF 2021

For 48 hours, participants will be able to solve tasks of all categories: web, reverse, pwn, forensics, crypto, OSINT, joy. Also new categories have been added: hardware, pentest and emulation!

https://yauzactf.com/en

Tuesday, January 12, 2021

NVIDIA DGX A100 Security Update


The DGX A100 System Firmware Update container version 20.11.3 for Ubuntu with BMC version 00.13.04 fixes vulnerabilities described in NVIDIA Security Bulletin 5010 such as CVE‑2020‑11487.


More details can be found in recent AISec talks and releases. 


Enjoy

Thursday, December 31, 2020

Vulnerabilities of Machine Learning Infrastructure (Slides/Video)

Vulnerabilities of Machine Learning Infrastructure talk as presented at CodeBlue 2020 Japan and Standoff365 by Sergey Gordeychik.

The boom of AI brought to the market a set of impressive solutions both on the hardware and software side. On the other hand, massive implementation of AI in various areas brings about problems, and security is one of the greatest concerns.

Saturday, November 14, 2020

Vulnerabilities of Machine Learning Infrastructure

As presented at The Standoff online cyber-range and security conference by Sergey Gordeychik.



In this talk we will present results of hands-on vulnerability research of different components of AI infrastructure including NVIDIA DGX GPU servers, ML frameworks such as Pytorch, Keras and Tensorflow, data processing pipelines and specific applications, including Medical Imaging and face recognition powered CCTV. Updated Internet Census toolkit based on the Grinder framework will be introduced.

Wednesday, October 28, 2020

NVIDIA DGX machine learning servers vulnerabilities

NVIDIA has published fixes for vulnerabilities in NVIDIA Machine learning servers with CVSS up to 9.8.

NVIDIA DGX-1, DGX-2, and DGX A100 Servers are affected and can be hacked via BMC OOB interfaces.