When publicly accessible with out authentication, these endpoints may reveal so much about a corporation’s computing infrastructure, Lava says. The techniques that have been discovered uncovered included Nvidia Blackwell Extremely B300 GPUs, H200s and H100s used for large-scale AI workloads, in addition to client RTX 5090 and 4090 techniques.
“Anybody who may attain these endpoints may see what {hardware} organizations have been operating, how closely it was getting used, and particulars in regards to the AI infrastructure round it,” Katchinskiy warned. Whereas such data doesn’t present entry to mannequin weights, coaching knowledge, or different protected belongings, it may assist an attacker profile a goal and establish weaker elements or software program variations.
Lava has beneficial proscribing public entry to DCGM Exporter and Prometheus except exterior entry is important, binding exporters to loopback or non-public interfaces, and implementing entry controls by firewalls, safety teams, or different community measures.


