Showing posts with label Releases. Show all posts
Showing posts with label Releases. Show all posts

Tuesday, January 12, 2021

NVIDIA DGX A100 Security Update


The DGX A100 System Firmware Update container version 20.11.3 for Ubuntu with BMC version 00.13.04 fixes vulnerabilities described in NVIDIA Security Bulletin 5010 such as CVE‑2020‑11487.


More details can be found in recent AISec talks and releases. 


Enjoy

Thursday, December 31, 2020

Vulnerabilities of Machine Learning Infrastructure (Slides/Video)

Vulnerabilities of Machine Learning Infrastructure talk as presented at CodeBlue 2020 Japan and Standoff365 by Sergey Gordeychik.

The boom of AI brought to the market a set of impressive solutions both on the hardware and software side. On the other hand, massive implementation of AI in various areas brings about problems, and security is one of the greatest concerns.

Saturday, November 14, 2020

Vulnerabilities of Machine Learning Infrastructure

As presented at The Standoff online cyber-range and security conference by Sergey Gordeychik.



In this talk we will present results of hands-on vulnerability research of different components of AI infrastructure including NVIDIA DGX GPU servers, ML frameworks such as Pytorch, Keras and Tensorflow, data processing pipelines and specific applications, including Medical Imaging and face recognition powered CCTV. Updated Internet Census toolkit based on the Grinder framework will be introduced.

Wednesday, October 28, 2020

NVIDIA DGX machine learning servers vulnerabilities

NVIDIA has published fixes for vulnerabilities in NVIDIA Machine learning servers with CVSS up to 9.8.

NVIDIA DGX-1, DGX-2, and DGX A100 Servers are affected and can be hacked via BMC OOB interfaces. 

Saturday, July 25, 2020

Vulnerabilities in AI Healthcare pipelines

Must see if you use/develop Artificial Intelligence in Healthcare and care about Cybersecurity and Privacy.


Monday, July 13, 2020

How to make your own Internet Census

Simple writeup on the Internet-scale census with example or Artificial Intelligence and Machine Learning infrastructure assessment by Antony Nikolaev. Sample Lab of Cybersecurity of Machine Learning and Artificial Intelligence at Harbour.Space University.

Just in case if you need spare Tensorboard in Africa or Kubeflow elsewhere.


Tuesday, June 2, 2020

A practical guide to SD-WAN Evil

Good writeup by Marcel Gamma. A story about Silverpeak SD-WAN vulnerabilities discovery / fixing / disclosure.


Tuesday, May 5, 2020

Malicious Portal SilverPeak REST API access

Details about new security vulnerabilities in SD-WAN solution. There is no authentication between cloud SilverPeak’s Portal on the Internet and customers’  EdgeConnect devices. EdgeConnect doesn’t authenticate Portal. Portal can execute any command on EdgeConnect via REST API.

Monday, April 20, 2020

SilverPeak’s IPsec UDP protocol implementation fails to provide forward secrecy

The IPsec UDP protocol implementation in SilverPeak EdgeConnect product fails to provide the claimed perfect forward secrecy property. Additionally, the product provides interfaces and has vulnerabilities that can be used to reconstruct the traffic encryption keys for all tunnels.


Tuesday, April 14, 2020

AI Finger 2020

New release of Internet census of Machine Learning and Artificial Intelligence Frameworks and Applications, April 2020.

Monday, December 30, 2019

Turbines, Simens, Vulnerabilities, Power

New release by Kaspersky team leaded by SCADA StrangeLove fellow Gleb Gritsai  "On the insecure nature of turbine control systems in power generation" as presented on Chaos Communication Congress 36C3.

Power plants everywhere...

Friday, December 6, 2019

Artificial Intelligence Security Census

In this paper, we present the results of Internet-wide security scans of publicly available AIML systems. We show that many different interfaces of AIML systems are not protected and accessible from the Internet, moreover, most of them don't even have basic security mechanisms. Also, we describe found the known vulnerabilities related to outdated software and insecure configurations. 

Thursday, November 14, 2019

Malign Machine Learning Models and bad DICOM

Zeronighs 2019 AISec releases: how to insert malware into TensorFlow and PyTorch models and hack NVIDIA Clara ML pipeline with DICOM image.


Wednesday, October 16, 2019

Cyber Resilience of Railway Signaling Systems

Recently published information on the cybersecurity assessment of railway computer and communication-based control systems (CBCS) identified several weaknesses and vulnerabilities, which allow threat agents to not only degrade system reliability and bypass safety mechanisms, but to carry out attacks which directly affect the rail traffic safety. Despite these findings, remarkably these systems meet all relevant IT security and functional safety requirements and have the required international, national and industrial certificates.

Monday, October 14, 2019

HITB AISec slides and special release

Slides "AI for Security and Security for AI" talk by Sergey Gordeychik, as presented at HITB CyberWeek 2019, Abu Dhabi.



Machine learning technologies are turning from rocket science into daily engineering life. You no longer have to know the difference between Faster R-CNN and HMM to develop a machine vision system, and even OpenCV has bindings for JavaScript allowing to resolve quite serious tasks all the while remaining in front end. On other hand massive implementation of AI in various areas brings about problems, and security is one of the greatest concerns. In the broader context security is really all about trust.

Do we trust AI? I don’t, personally.

Thursday, October 10, 2019

DICOM to passwd. On security of ML pipelines

Machine Learning and Artificial Intelligence Pipelines are very useful tools. They help to concentrate on specific task without digging into implementation details. However, from design and security perspective these things are like Frankenstein.

Here is  an example


Sunday, September 29, 2019

Wednesday, September 11, 2019

Silverpeak SD-WAN +7 CVE

Fixed (?) published. Kudos SD-WAN New Hop team: Sergey Gordeychick, Denis Kolegov, Maxim Gorbunov, Nikolay Tkachenko, Nikita Oleksov, Oleg Broslavsky, Antony Nikolaev