Critical remote code execution vulnerabilities have been discovered in major AI inference engines from Meta, Nvidia, Microsoft, and open-source projects like vLLM and SGLang. The flaws stem from unsafe deserialization of Python's pickle module over ZeroMQ sockets, a pattern called ShadowMQ that spread through code reuse across

4m read time From thehackernews.com
Post cover image

Sort: