05/11

RCEliteLLM – LiteLLM 1.83.14: Chaining an Environment Variable Leak with Jinja2 SSTI for Remote Code Execution – McCaulay

https://mccaulay.co.uk/rcelitellm-litellm-1-83-14-chaining-an-environment-variable-leak-with-jinja2-ssti-for-remote-code-execution/
RCEliteLLM – LiteLLM 1.83.14: Chaining an Environment Variable Leak with Jinja2 SSTI for Remote Code Execution – McCaulay

株式会社Ikotas Labs

https://ikotaslabs.com/
株式会社Ikotas Labs

Google: Hackers used AI to develop zero-day exploit for web admin tool

https://www.bleepingcomputer.com/news/security/google-hackers-used-ai-to-develop-zero-day-exploit-for-web-admin-tool/
Google: Hackers used AI to develop zero-day exploit for web admin tool

Mythos finds a curl vulnerability | daniel.haxx.se

https://daniel.haxx.se/blog/2026/05/11/mythos-finds-a-curl-vulnerability/
Mythos finds a curl vulnerability | daniel.haxx.se

Canvas System Is Online After a Cyberattack Disrupted Thousands of Schools - SecurityWeek

https://www.securityweek.com/canvas-system-is-online-after-a-cyberattack-disrupted-thousands-of-schools/
Canvas System Is Online After a Cyberattack Disrupted Thousands of Schools - SecurityWeek

Fake OpenAI Privacy Filter Repo Hits #1 on Hugging Face, Draws 244K Downloads

https://thehackernews.com/2026/05/fake-openai-privacy-filter-repo-hits-1.html
Fake OpenAI Privacy Filter Repo Hits #1 on Hugging Face, Draws 244K Downloads

Skoda Data Breach Hits Online Shop Customers - SecurityWeek

https://www.securityweek.com/skoda-data-breach-hits-online-shop-customers/
Skoda Data Breach Hits Online Shop Customers - SecurityWeek

Python Backdoor Threat Analysis Following an AI Deepfake Impersonation Campaign

https://www.genians.co.kr/en/blog/threat_intelligence/python
Python Backdoor Threat Analysis Following an AI Deepfake Impersonation Campaign

Crimenetwork returns after takedown, dismantled again by German authorities

https://securityaffairs.com/191969/cyber-crime/crimenetwork-returns-after-takedown-dismantled-again-by-german-authorities.html
Crimenetwork returns after takedown, dismantled again by German authorities

Instructure confirms hackers used Canvas flaw to deface portals

https://www.bleepingcomputer.com/news/security/instructure-confirms-hackers-used-canvas-flaw-to-deface-portals/
Instructure confirms hackers used Canvas flaw to deface portals

Google Detects First AI-Generated Zero-Day Exploit - SecurityWeek

https://www.securityweek.com/google-detects-first-ai-generated-zero-day-exploit/
Google Detects First AI-Generated Zero-Day Exploit - SecurityWeek

SailPoint Discloses GitHub Repository Hack - SecurityWeek

https://www.securityweek.com/sailpoint-discloses-github-repository-hack/
SailPoint Discloses GitHub Repository Hack - SecurityWeek

Resurrected 'Crimenetwork' Marketplace Taken Down, Administrator Arrested - SecurityWeek

https://www.securityweek.com/resurrected-crimenetwork-marketplace-taken-down-administrator-arrested/
Resurrected 'Crimenetwork' Marketplace Taken Down, Administrator Arrested - SecurityWeek

New 'Dirty Frag' Linux Vulnerability Possibly Exploited in Attacks - SecurityWeek

https://www.securityweek.com/new-dirty-frag-linux-vulnerability-possibly-exploited-in-attacks/
New 'Dirty Frag' Linux Vulnerability Possibly Exploited in Attacks - SecurityWeek

Police shut down reboot of Crimenetwork marketplace, arrest admin

https://www.bleepingcomputer.com/news/security/police-shut-down-reboot-of-crimenetwork-marketplace-arrest-admin/
Police shut down reboot of Crimenetwork marketplace, arrest admin

Checkmarx Jenkins AST Plugin Compromised in Supply Chain Attack - SecurityWeek

https://www.securityweek.com/checkmarx-jenkins-ast-plugin-compromised-in-supply-chain-attack/
Checkmarx Jenkins AST Plugin Compromised in Supply Chain Attack - SecurityWeek