Hackers Exploit LiteLLM Admin API Flaw to Steal Secrets and Target AI Gateway Servers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Attackers are actively probing LiteLLM AI gateway deployments for a known authorization flaw that can turn a low-privilege account into full administrative control. The issue, tracked as CVE-2026-35029, affects LiteLLM …

Hackers Pose as IT Support on Microsoft Teams to Take Remote Control of Windows PCs

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals are posing as IT technicians on Microsoft Teams and persuading employees to hand over control of their Windows computers. The campaign turns a familiar support conversation into a direct …

Silver Fox-Linked Hackers Use Fake Software Installers to Disable Microsoft Defender and Compromise Windows Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Silver Fox-linked hackers are using counterfeit software installers to break into Windows systems and weaken the protections meant to stop them. The campaign relies on convincing download pages that copy …

Critical SonicWall Remote Code Execution Vulnerabilities Actively Exploited in Attacks

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

SonicWall has warned that attackers are actively exploiting two critical vulnerabilities affecting SMA1000 Series secure mobile access appliances. The flaws could allow unauthenticated attackers to access sensitive functionality and enable …

Critical HPE Fabric Composer Flaws Let Unauthenticated Attackers Execute Code and Take Over Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

HPE has released security updates for HPE Networking Fabric Composer following the discovery of a large set of vulnerabilities that could allow unauthenticated attackers to gain administrator access, run arbitrary …

Hackers Hide a Full Remote Access Trojan Inside a Real Exodus Crypto Wallet

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Cybercriminals have been caught using a tampered installer for the Exodus cryptocurrency wallet to plant a full remote access trojan. The program looks close enough to the real wallet, but …

Google Fixes 26 Chrome Vulnerabilities, Including 2 Critical Use-After-Free Flaws

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has released Chrome 152.0.7977.75/.76 for Windows and macOS and Chrome 152.0.7977.75 for Linux, addressing 26 security vulnerabilities across the browser. The update includes two critical use-after-free flaws affecting Shared …

Hugging Face Flaw Lets Malicious AI Models Plant Python Code on User Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A newly disclosed vulnerability in Hugging Face Transformers could allow malicious AI model repositories to place attacker-controlled Python files on a user’s system before the user approves remote code execution. …

OpenAI’s New Astra AI Can Discover Zero-Day Security Flaws and Build Exploits

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

OpenAI says its upcoming Astra model has reached the company’s Critical cybersecurity capability threshold, meaning it can independently discover unknown vulnerabilities and develop working exploits against hardened systems when given …

Anthropic Launches Claude Fable and Mythos 5.1 for Advanced Coding and Research

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Anthropic has rolled out two new frontier AI models, Claude Fable 5.1 and Claude Mythos 5.1, positioning them as the most capable systems yet for software development, enterprise knowledge work, …