<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Megatron LM &#8211; 科技島-掌握科技新聞、科技職場最新資訊</title>
	<atom:link href="https://www.technice.com.tw/tag/megatron-lm/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.technice.com.tw</link>
	<description>專注於科技新聞、科技職場、科技知識相關資訊，包含生成式AI、人工智慧、Web 3.0、區塊鏈、科技職缺百科、生物科技、軟體發展、雲端技術等豐富內容，適合熱衷科技及從事科技專業人事第一手資訊的平台。</description>
	<lastBuildDate>Thu, 26 Jun 2025 03:01:19 +0000</lastBuildDate>
	<language>zh-TW</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.4.2</generator>

<image>
	<url>https://www.technice.com.tw/wp-content/uploads/2022/12/cropped-wordpress_512x512-150x150.png</url>
	<title>Megatron LM &#8211; 科技島-掌握科技新聞、科技職場最新資訊</title>
	<link>https://www.technice.com.tw</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>輝達Megatron LM驚爆「程式碼注入」嚴重漏洞 系統恐遭駭客入侵</title>
		<link>https://www.technice.com.tw/techmanage/infosecurity/179032/</link>
					<comments>https://www.technice.com.tw/techmanage/infosecurity/179032/#respond</comments>
		
		<dc:creator><![CDATA[孫敬]]></dc:creator>
		<pubDate>Thu, 26 Jun 2025 03:01:19 +0000</pubDate>
				<category><![CDATA[資安]]></category>
		<category><![CDATA[生活]]></category>
		<category><![CDATA[Megatron LM]]></category>
		<category><![CDATA[半導體]]></category>
		<category><![CDATA[輝達]]></category>
		<guid isPermaLink="false">https://www.technice.com.tw/?p=179032</guid>

					<description><![CDATA[<p>輝達近日證實，其用於大型語言模型（LLM）開發的Megatron LM框架存在嚴重的安全漏洞。<content><span style="font-weight: 400;">記者孫敬／編譯<br />
</span><span style="font-weight: 400;"><br />
</span><span style="font-weight: 400;"><a href="https://www.technice.com.tw/?s=%E8%BC%9D%E9%81%94" target="_blank" rel="noopener">輝達</a>（NVIDIA）近日證實，其用於大型語言模型（LLM）開發的Megatron LM框架存在嚴重的安全漏洞。這些漏洞可能允許攻擊者植入惡意程式碼，進而取得未經授權的系統存取權限。據報，輝達已於2025年6月24日緊急發布安全修補程式，修復0.12.0版本前的漏洞</span></p>
<p><b>延伸閱讀：<a href="https://www.technice.com.tw/issues/semicon/177894/" target="_blank" rel="noopener">再砍中國一刀！傳輝達推GeForce RTX 5090 D降規版本GeForce RTX 5090 DD</a></b></p>
<p>[caption id="attachment_88859" align="aligncenter" width="1200"]<img class="wp-image-88859 size-full" src="https://www.technice.com.tw/wp-content/uploads/2024/01/輝達NVIDIA_166775280_fb-link_normal_none-6.jpg" alt="" width="1200" height="627" /> Megatron LM漏洞補丁已經推出。（圖／科技島圖庫）[/caption]</p>
<h2><b>低權限高危害，輝達呼籲用戶立即更新強化防禦</b></h2>
<p><span style="font-weight: 400;">本次發現Megatron LM的兩項重大安全缺陷，分別被標記為 CVE-2025-23264 和 CVE-2025-23265。這兩項漏洞均源於Python框架下的程式碼弱點，在通用缺陷列表（CWE）中歸類為CWE-94（程式碼注入），漏洞的CVSS v3.1基礎評分高達7.8分，被列為高嚴重性威脅。資安研究員Yu Rong和Hao Fan發現後，便向輝達產品資安事件應變小組（PSIRT）報告。這些漏洞對於利用輝達框架，進行大規模語言模型訓練和推論的組織而言構成重大風險。</span></p>
<p><span style="font-weight: 400;">這兩項漏洞的攻擊途徑均為 AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H。這代表攻擊者僅需具備本地存取權限，攻擊複雜性低，且所需權限也低，無需使用者互動即可發動攻擊。攻擊者可透過向Megatron LM系統提供特製的惡意檔案來入侵這些漏洞。一旦成功，攻擊者可能造成多種嚴重後果，包括程式碼執行、權限提升、資訊洩露以及數據篡改。</span></p>
<p><span style="font-weight: 400;">輝達強烈<a href="https://nvidia.custhelp.com/app/answers/detail/a_id/5663" target="_blank" rel="noopener">建議</a>所有Megatron LM用戶立即更新至0.12.1或更高版本，相關<a href="https://github.com/NVIDIA/Megatron-LM" target="_blank" rel="noopener">更新</a>已在其官方GitHub，而本次安全更新同時解決了CVE-2025-23264和CVE-2025-23265兩項缺陷。運行較舊軟體分支版本的用戶，應升級至最新的分支版本，以確保獲得全面保護。輝達強調，其風險評估是基於各種安裝環境的平均值，個別組織仍應評估其特定配置所面臨的風險。</span></p>
<p><span style="font-weight: 400;">資料來源：<a href="https://cybersecuritynews.com/nvidia-megatron-lm-vulnerability/" target="_blank" rel="noopener">Cyber Security</a></span></content></p>
<p>這篇文章 <a rel="nofollow" href="https://www.technice.com.tw/techmanage/infosecurity/179032/">輝達Megatron LM驚爆「程式碼注入」嚴重漏洞 系統恐遭駭客入侵</a> 最早出現於 <a rel="nofollow" href="https://www.technice.com.tw">科技島-掌握科技新聞、科技職場最新資訊</a>。</p>
]]></description>
		
					<wfw:commentRss>https://www.technice.com.tw/techmanage/infosecurity/179032/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
