Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. Another AI service that's dangerous when exposed to the internet?

Another AI service that's dangerous when exposed to the internet?

Scheduled Pinned Locked Moved Uncategorized
cvethreatintelthreatintelligeifin
2 Posts 1 Posters 4 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • ifin@infosec.exchangeI This user is from outside of this forum
    ifin@infosec.exchangeI This user is from outside of this forum
    ifin@infosec.exchange
    wrote last edited by
    #1

    Another AI service that's dangerous when exposed to the internet? Well I never!

    Anyway go check for exposed Ollama endpoints.

    Link Preview Image
    Unauthenticated Memory Leak in Ollama (CVE-2026-7482)

    Details: Cyera disclosed a heap out-of-bounds read issue that exists in Ollama (before 0.17.1). This can be exploited to access sensitive information stored on the heap, including prompts, messages, and environment vari…

    favicon

    IFIN (discourse.ifin.network)

    #CVE #ThreatIntel #ThreatIntelligence #IFIN

    ifin@infosec.exchangeI 1 Reply Last reply
    1
    0
    • ifin@infosec.exchangeI ifin@infosec.exchange

      Another AI service that's dangerous when exposed to the internet? Well I never!

      Anyway go check for exposed Ollama endpoints.

      Link Preview Image
      Unauthenticated Memory Leak in Ollama (CVE-2026-7482)

      Details: Cyera disclosed a heap out-of-bounds read issue that exists in Ollama (before 0.17.1). This can be exploited to access sensitive information stored on the heap, including prompts, messages, and environment vari…

      favicon

      IFIN (discourse.ifin.network)

      #CVE #ThreatIntel #ThreatIntelligence #IFIN

      ifin@infosec.exchangeI This user is from outside of this forum
      ifin@infosec.exchangeI This user is from outside of this forum
      ifin@infosec.exchange
      wrote last edited by
      #2

      As a chaser, here are two other CVEs on Ollama from yesterday.

      Link Preview Image
      CVE-2026-42248, CVE-2026-42249: Ollama on Windows doesn't verify updates, writes anywhere

      Oh cool Ollama on Windows has unpatched vulnerabilities that lead to Ollama downloading unverified updates from a malicious URL if set locally, and also a path traversal vulnerability leads to arbitrary file write. CVE-…

      favicon

      IFIN (discourse.ifin.network)

      1 Reply Last reply
      1
      0
      • R relay@relay.infosec.exchange shared this topic
        mttaggart@infosec.exchangeM mttaggart@infosec.exchange shared this topic
      Reply
      • Reply as topic
      Log in to reply
      • Oldest to Newest
      • Newest to Oldest
      • Most Votes


      • Login

      • Login or register to search.
      • First post
        Last post
      0
      • Categories
      • Recent
      • Tags
      • Popular
      • World
      • Users
      • Groups