BLOG

Root on Every GPU Container Start: Catching NVIDIA Container Toolkit Compromise
SECURITYNVIDIAGPU

Root on Every GPU Container Start: Catching NVIDIA Container Toolkit Compromise

The NVIDIA Container Toolkit is mandatory, privileged, and almost entirely unmonitored — and most detection content written for it watches binaries that no longer execute. One docker run --gpus all produced six root executions of nvidia-cdi-hook on our test host, before the workload's first instruction. Here is what actually runs on a modern GPU node, and how Stealthium separates legitimate hook execution from abuse.

AUG 2026Stealthium Security Research Team
ShadowRay 2.0: Turning Exposed Ray Clusters Into a GPU-Mining Botnet — and How Stealthium Catches It
SECURITYAIGPU

ShadowRay 2.0: Turning Exposed Ray Clusters Into a GPU-Mining Botnet — and How Stealthium Catches It

An internet-exposed Ray dashboard is an open door: an unauthenticated job submission runs attacker code on every node, and within minutes a crypto-miner is pinning your GPUs while your model weights walk out — all while monitoring reports a training job as running. We reproduced the ShadowRay 2.0 kill chain end to end against a real Ray cluster on an NVIDIA L40S and watched Stealthium catch every stage, from the unauthenticated request to the CUDA proof-of-work kernel.

AUG 2026Stealthium Security Research Team
Substrate AI and Stealthium Partner to Deliver Runtime Security for AI Infrastructure
PARTNERSHIPSSECURITYAI

Substrate AI and Stealthium Partner to Deliver Runtime Security for AI Infrastructure

As artificial intelligence infrastructure scales across enterprises and public sector organizations, security, transparency, and compliance have become critical operating requirements. Modern AI environments are highly distributed, GPU-accelerated, and often shared across multiple tenants, yet visibility and runtime protection at the GPU layer remain limited.

JAN 2026Stealthium Security Research Team