Blog

Featured
CVE-2026-47483: How We Could Disrupt Thousands of Exposed GPU Servers
We found a high-severity vulnerability in NVIDIA’s GPU exporter that could let attackers crash monitoring and potentially disrupt AI workloads without authentication. We also uncovered 2,100 servers leaking telemetry from 12,000+ GPUs to anyone online.
Be the first to know about product updates, security research, and new blog posts from Lava.

CVE-2026-47483: How We Could Disrupt Thousands of Exposed GPU Servers
Michael KatchinskiyWe found a high-severity vulnerability in NVIDIA’s GPU exporter that could let attackers crash monitoring and potentially disrupt AI workloads without authentication. We also uncovered 2,100 servers leaking telemetry from 12,000+ GPUs to anyone online.

The Next AI Attack May Happen Inside the Data Center
Yakir KadkodaAI is moving faster than the infrastructure beneath it. As neoclouds and data centers race to support increasingly powerful AI workloads and autonomous agents, the security models protecting that infrastructure are struggling to keep up with the pace of change.

An Open Letter to Neoclouds: Security Has to Catch Up

Yakir Kadkoda and Michael KatchinskiyNeocloud security failures are exposing tenant boundaries, management infrastructure, and shared systems that should never be reachable.

Neocloud Security: You're Trusting Your Provider More Than You Should
Michael KatchinskiyRenting GPUs from a neocloud means trusting far more than the compute itself. Lava’s research has highlighted risks in that infrastructure. Separately, SemiAnalysis’s ClusterMAX 3.0 testing shows why customers should look beyond GPU availability when evaluating neocloud security.

Rethinking the Shared Responsibility Model for NeoCloud Security
Yakir KadkodaAI infrastructure adds security-relevant layers below the customer’s direct control. Modern shared responsibility models need to show not only who operates those layers, but how they can affect the customer and what assurance the provider provides.

How We Hacked Thousands of Data Centers in Minutes Using a 20-Year-Old Vulnerability
Michael KatchinskiyA 20-year-old vulnerability gave us access to bare-metal servers - and a foothold in the no man’s land of data center infrastructure.

Securing the Metal Beneath the Model: Two Big Shifts Exposing AI Data Center
Eyal SoreffWhile the security industry fixates on model risks, AI data centers are creating a dangerous blind spot. Rapid, bare-metal deployments have left hardware security lagging. We are introducing FORGE, a community-driven framework designed to secure the "metal beneath the model" and fix critical infrastructure gaps.

Breaking the Trust: Firmware Compromise in Modern Infrastructure
Michael KatchinskiyA look at real-world firmware attacks targeting UEFI, BMCs, and GPUs to gain stealthy, persistent access below the operating system.

Breaking the Trust: Enforcing Firmware Integrity
Yakir KadkodaFirmware inventory can reveal what version a device reports, but it cannot prove that the firmware currently running is genuine. This blog explains how hardware-backed attestation, SPDM, ERoTs, and CoRIMs enable organizations to move from self-reported visibility to cryptographically verified firmware trust.

Breaking the Trust: Introducing Firmware Integrity
Yakir KadkodaFirmware runs before the operating system and controls the hardware beneath it. Maintaining its integrity is essential to ensuring that modern infrastructure starts, and remains, in a trusted state.

The Runtime Gap: Introducing Runtime Integrity
Yakir KadkodaWhen machines move between tenants, AI infrastructure teams face a real trade-off: reboot for safety and lose valuable GPU time, or rely on partial cleanup and risk a compromise lurking beneath the surface.

The Runtime Gap: Runtime Attacks in Modern Infrastructure
Michael KatchinskiyFrom kernel rootkits to eBPF backdoors, attackers are targeting the deepest layers of your infrastructure to gain persistent, undetectable access. Once they control the runtime, every monitoring tool you trust can be lying to you.

The Runtime Gap: Enforcing Runtime Integrity
Yakir KadkodaAttackers operate after boot, manipulating kernels, injecting libraries, and hiding in plain sight. Traditional trust models can't keep up. It's time to shift from static trust to continuous runtime verification.
No posts in this category yet.