Skip to content
VECTOR WIREAI INTELLIGENCE
UTC

ALL BRIEFS

RANKED · 9 THIS DAY

vLLM Discloses Unauthenticated DoS Flaw in Qwen Video Backends

A medium-severity vulnerability (CVE-2026-105758) in vLLM allows unauthenticated remote attackers to exhaust API-server memory on deployments serving Qwen2-VL or Qwen3-VL models by manipulating request-level max_frames and fps parameters…

3d ago·Industry ProSINGLE SOURCE

Evaluation gates force AI teams to prove ROI before scaling

New data on AI agent economics sharpens the case for formal proof gates: Gartner forecasts worldwide AI spending will reach $2.7 trillion this year, up 49.5% year-on-year, yet Splunk executives say enterprises still lack a reliable way to…

The Vector·2d ago·Industry ProUPDATED10 INDEPENDENT OUTLETS

Meta, Walmart, and Stripe back Personal Agent Protocol to govern AI-bot commerce

Sierra co-founder Bret Taylor, who also chairs OpenAI's board, introduced the Personal Agent Protocol alongside Meta, Walmart, Stripe, and a handful of other companies on October 6, framing the effort as a response to the "chaos" that…

2d ago·Industry ProUPDATED2 INDEPENDENT OUTLETS

GitLab AI Gateway flaw scores CVSS 9.9, grants host-level command execution

A server-side template injection in GitLab AI Gateway lets an authenticated user break out of the prompt-template sandbox and execute arbitrary commands on the gateway host, shattered.io reported, citing GitLab's own advisory along with…

2d ago·Industry Pro2 INDEPENDENT OUTLETS

vLLM cache_salt flaw lets one request crash EngineCore on LMCache-MP deployments

A medium-severity vulnerability in vLLM allows a single malicious API request to crash the serving engine for all concurrent users on deployments running the LMCache-MP KV connector, according to a GitHub security advisory . The advisory…

3d ago·Industry ProSINGLE SOURCE