About this talk
This talk examines the critical security risks inherent in AI-generated containers, particularly focusing on the vulnerabilities present in typical Ollama containers that contain numerous unnecessary packages. The speaker discusses real exploit scenarios, including CVE-2024-37032, which showcases how a simple HTTP request can lead to a full container takeover. The session emphasizes the importance of removing superfluous components to mitigate risks and addresses threats from supply chain attacks like Shai-Hulud. Through detailed examples, SBOM analysis, and exploit walkthroughs, the talk illustrates the necessity of foundation-first security in AI-driven development, highlighting strategies to minimize exposure at the base layer.
More from this event
See all 126 talks →
AI Is Not the Risk. Architectural Drift Is - Sunil Kalkunte
17:39
Breaking the Monolith: Tesco’s Journey to Federated GraphQL with xAPI - Vishwas Chandrashekar
29:13
A Practical Introduction to LangChain4j - Venkat Subramaniam
1:01:28
Beyond the AI Models: How Lowe’s is Building the Store That Knows - Swaroop Shivaram
13:59