Artificial Intelligence (AI)
Wiz Research: Nearly 1-in-10 Exposed LiteLLM Gateways Accepted the Example "sk-1234" Admin Key
One example admin key from a setup guide, nearly ten percent of gateways accepting it. LiteLLM hygiene lands this week.
Insights on credential attacks, including credential stuffing, password spraying, and account takeovers, with strategies to detect, prevent, and secure user authentication systems.
Artificial Intelligence (AI)
One example admin key from a setup guide, nearly ten percent of gateways accepting it. LiteLLM hygiene lands this week.
Supply Chain Attack
The npm ecosystem's worst day of the summer. A self-propagating worm Microsoft calls ChainDrop hit 440-plus packages in under four hours, and a Keyv-linked chain poisoned as many as 868 — planting Claude Code and VS Code hooks in compromised environments.
Supply Chain Attack
For the second time in weeks, Microsoft packages were laced with credential stealers — this time targeting users of AI coding agents, forcing the company to pull more than 70 of its own GitHub repositories.
Vulnerabilities
Researcher Ammar Askar disclosed a one-click attack via VS Code's GitHub.dev that steals a GitHub OAuth token with read-write access to private repos. He published the PoC with about an hour's notice, blaming Microsoft's disclosure process.
Password Security
Dashlane confirmed that an external party brute-forced the token check on its new-device-registration flow, and the company's automatic protections suspended targeted accounts. The lockout is the protection working — the news is what attackers went after.
Social Engineering
A phishing wave is impersonating Signal Support to ask users for their secret recovery key — the key that decrypts online backups containing past messages. The defender utility is simple: Signal will never ask for it, ever.
Data Breaches
A threat actor advertised a 340 million-record OnlyFans dataset for 0.313 BTC on May 25, then privately admitted they did not breach the platform. The compilation stitches old breach data to public profiles, and the framing failure is itself the editorial story.
Phishing
The FBI's IC3 has warned organizations about Kali365, a Telegram-sold phishing-as-a-service kit that runs device-code phishing against Microsoft 365 — stealing the OAuth tokens issued after the victim genuinely passes MFA on Microsoft's real sign-in page.
Social Engineering
The Based Apparel merchandise site was pulled offline on May 22 after reports it served a ClickFix attack: a fake Cloudflare check whose copy button placed a hidden shell command on the clipboard for visitors to paste into their own terminal.
Vulnerabilities
Qualys disclosed CVE-2026-46333 — 'ssh-keysign-pwn' — a nine-year-old Linux kernel ptrace flaw that gives an unprivileged user root. Its defining feature is credential theft: the exploit captures SSH keys and shadow-file password hashes, so a patched kernel does not end the exposure.
Application Security
Norwegian researcher Tom Jøran Sønstebyseter Rønning of Statnett SF demonstrated at the Palo Alto Networks Norway BIG Bite of Tech conference that Microsoft Edge keeps every saved password loaded in plaintext RAM during a browser session. Microsoft's response: by design.
Cyber Attacks
Ukrainian police have arrested three individuals who systematically used stolen session cookies to access and sell more than 610,000 Roblox accounts, targeting profiles with accumulated in-game currency and rare items and reselling them through Russian criminal platforms for cryptocurrency. KYIV, UKRAINE — Ukrainian law enforcement has detained three suspects