Terabytes worth of credentials, many belonging to the world’s biggest and most sensitive organizations, have been exposed in a supply-chain attack on LiteLLM, an open source tool that streamlines ...
The March 2026 LiteLLM supply chain attack likely affected over 2,500 organizations and exposed over 430,000 CI/CD pipelines.
AI agent tool bypass vulnerability CoreBreak exposed production agent infrastructure at AWS, Google, and Vercel, where attackers could invoke tools without any model turn. AWS fixed its managed ...
On March 24, 2026, developers building AI applications with LiteLLM — a Python package with 95 million monthly downloads — ...
AI agent flaws in AWS, Google, and Vercel let forged tool calls reach tools without model authorization, while several paths ...
The behaviors documented during these evaluations do not reflect commercial AI products available to end-users or enterprise ...
Security researcher James Kettle tried to push the limit of AI’s hacking abilities—and discovered how effective it can be when combined with human expertise.
A roundup of the latest noteworthy AI-assisted attacks, threats, risks, and vulnerabilities, and what they portend for cyber defense.
Google removed 3 ADK AI workflows after Pillar showed a public GitHub issue could trigger a privileged agent & reach code ...
A low-privilege Google ADK for Python agent could be abused to inject prompts into privileged agents, leading to PR poisoning ...
According to new research from Blackpoint Cyber's Adversary Pursuit Group (APG), published on July 30, the intrusion hit two ...