LiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway Servers
LiteLLM is a widely deployed open-source AI gateway that brokers calls to more than 100 model providers behind one OpenAI-compatible interface.
A server takeover exposes every provider key it holds, the secrets that
Council of Europe investigates ShinyHunters data breach claims
FBI: Fraudsters use couriers to steal money in crypto scams
Ransomware Attack Shuts Down Mills of Australia’s Second-Largest Sugar Producer
Mackay Sugar was targeted in a cyberattack carried out by a threat group known as The Gentlemen.
The post Ransomware Attack Shuts Down Mills of Australia’s Second-Largest Sugar Producer appeared first on SecurityWeek.
One-Click Microsoft 365 Copilot Flaw Could Have Let Attackers Steal Emails, Files, and MFA Codes
Researchers at Varonis Threat Labs chained three bugs into a one-click exfiltration path they call SearchLeak. Because the link pointed to a real microsoft.com domain, traditional anti-phishing and URL filtering tools were
Chinese Hackers Target Medical, Military, and AI Research in North America
Google’s Threat Intelligence Group has been tracking the cyberespionage group as UNC6508 since early 2025.
The post Chinese Hackers Target Medical, Military, and AI Research in North America appeared first on SecurityWeek.
Vibe coders are gonna vibe code: How CISOs are tackling code sprawl
Chinese hackers breach REDCap servers, steal medical research
⚡ Weekly Recap: Chrome 0-Day, UniFi Exploits, macOS Stealers, VPN Flaw and More
This week is the same lesson in a new form: phishing kits are easier to rent, AI names are useful bait, old login paths still fail, and forgotten software keeps becoming someone else’s entry point.
Scroll through the full Monday Cybersecurity
