A compromised AWS-hosted AI gateway tied to Amazon Bedrock shows how generative AI middleware can become valuable enough to hijack for cryptocurrency mining.
A critical authentication bypass in a widely used LLM proxy shows how a classic web flaw can become far more serious when it hits the control plane.
A critical CVE in the AI proxy layer shows how a client-controlled Host header can split routing from authorization and turn a management plane into a soft target.
A reported LiteLLM flaw chain shows how a proxy that concentrates access, secrets, and admin power can turn a low-privilege account into a gateway-level security event.
A LiteLLM vulnerability chain underscores how one command-injection path and one Host-header trust flaw can collide into a high-risk control-plane exposure.
A chained flaw in an AI proxy gateway shows how preview and diagnostic endpoints can cross the line from convenience to host-level risk when they can launch subprocesses.
A high-severity LiteLLM command-injection bug shows how AI gateway control panels can collapse into host-level risk when role checks are too loose.
A reported campaign tied to TeamPCP shows how a single AI middleware package can become a high-value path to secrets, even when the exact compromise method remains unclear.
A sanctioned exploit contest put Microsoft Edge, Windows 11, LiteLLM, and NVIDIA-related technologies under pressure, showing how today’s attack surface reaches from the browser sandbox to AI control planes.
A controlled exploit contest in Berlin turned into a stress test for modern security layers, with researchers demonstrating 24 unique zero-days across Microsoft Edge, Windows 11, LiteLLM, and NVIDIA-related targets.
A PyPI version with no matching upstream trail turned a routine dependency check into a lesson in software provenance, release governance, and build-time trust.
A critical SQL injection in LiteLLM was weaponized within hours, exposing API keys and credentials before most users could react.
A critical SQL injection flaw in the popular AI gateway LiteLLM was weaponized within hours, exposing cloud credentials and raising fresh alarms for open-source security.
A critical SQL injection bug in LiteLLM let attackers raid sensitive databases, exposing the backbone of countless AI apps.
A critical vulnerability in LiteLLM exposes sensitive AI infrastructure, with attackers moving at record speed to steal secrets and credentials.
A newly discovered SQL injection vulnerability in LiteLLM exposes valuable API keys and credentials, escalating the threat to core AI infrastructure.
AI recruiter Mercor is among thousands caught in the LiteLLM supply chain attack, raising fresh alarms about the fragility of open-source software security.
A sophisticated malware campaign poisons LiteLLM, risking millions of AI projects and cloud environments worldwide.
A trusted AI developer tool is weaponized in a sweeping supply-chain attack, exposing secrets from hundreds of thousands of systems worldwide.
A sophisticated backdoor campaign exploits software supply chains, exposing thousands of environments through cascading compromises.