Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: dns-rebinding (2 articles)Clear

Malicious webpage can hijack a local AI agent via NVIDIA NemoClaw and Ollama

Researchers disclosed a flaw in NVIDIA NemoClaw, a stack for running AI agents like OpenClaw with local inference through Ollama, that lets a single malicious webpage hijack the agent. Tracked as CVE-2026-65105, the issue is that NemoClaw starts Ollama bound to all network interfaces, so a DNS-rebinding attack from a page the user simply visits reaches the local model server and takes unauthenticated control. The attacker can then rewrite the model's chat template to plant hidden instructions that run on every later inference, beneath the agent's own guardrails and persisting across conversations. A fix landed in version 0.0.35 for macOS and Linux, but the Windows path remains exposed.

Check
Update NemoClaw to 0.0.35 on macOS and Linux, bind Ollama to the loopback address instead of all interfaces, and firewall port 11434, treating the local model server as a critical service.
Affected
Developers running NemoClaw with a local Ollama backend (CVE-2026-65105); a visited malicious page can hijack the model server via DNS rebinding and persistently poison the model, with the Windows path still unfixed.
Fix
Patch where a fix exists, restrict Ollama to loopback and firewall its port, monitor for chat-template changes, and limit the tools, source control, and cloud access the agent holds to reduce impact.

CISA flags exploited Ray flaw that lets a website run code on developer machines

CISA added a critical flaw in Ray, the open-source framework for scaling AI and machine-learning workloads, to its exploited-vulnerabilities catalog and gave federal agencies just three days to fix it. Tracked as CVE-2025-62593 and scored 9.4, the bug stems from Ray leaving key dashboard and job endpoints unauthenticated; its only browser defense checked that the request's user-agent began with Mozilla, which attackers can forge. Combined with a DNS rebinding attack, a malicious website or advertisement viewed while running Ray can execute code on the developer's machine. A DDoS botnet adopted it before public disclosure, and a separate campaign has been turning unpatched Ray clusters with GPUs into cryptocurrency miners.

Check
Upgrade Ray to version 2.52.0 or later, and treat the risk as immediate given the three-day federal deadline and ongoing campaigns against exposed clusters, including developer machines running Ray locally.
Affected
Anyone running Ray before 2.52.0 (CVE-2025-62593); unauthenticated dashboard endpoints plus a browser and DNS rebinding attack let a malicious page run code on the machine, and it is exploited in the wild.
Fix
Patch to 2.52.0, keep Ray dashboards and APIs off untrusted networks and behind authentication, restrict who can reach them, and check GPU clusters for unauthorized cryptomining and other signs of compromise.