RCEliteLLM – LiteLLM 1.83.14: Chaining an Environment Variable Leak with Jinja2 SSTI for Remote Code Execution – McCaulay
https://mccaulay.co.uk/rcelitellm-litellm-1-83-14-chaining-an-environment-variable-leak-with-jinja2-ssti-for-remote-code-execution/
株式会社Ikotas Labs
https://ikotaslabs.com/
Google: Hackers used AI to develop zero-day exploit for web admin tool
https://www.bleepingcomputer.com/news/security/google-hackers-used-ai-to-develop-zero-day-exploit-for-web-admin-tool/
Mythos finds a curl vulnerability | daniel.haxx.se
https://daniel.haxx.se/blog/2026/05/11/mythos-finds-a-curl-vulnerability/
Canvas System Is Online After a Cyberattack Disrupted Thousands of Schools - SecurityWeek
https://www.securityweek.com/canvas-system-is-online-after-a-cyberattack-disrupted-thousands-of-schools/
Fake OpenAI Privacy Filter Repo Hits #1 on Hugging Face, Draws 244K Downloads
https://thehackernews.com/2026/05/fake-openai-privacy-filter-repo-hits-1.html
Skoda Data Breach Hits Online Shop Customers - SecurityWeek
https://www.securityweek.com/skoda-data-breach-hits-online-shop-customers/
Python Backdoor Threat Analysis Following an AI Deepfake Impersonation Campaign
https://www.genians.co.kr/en/blog/threat_intelligence/python
Crimenetwork returns after takedown, dismantled again by German authorities
https://securityaffairs.com/191969/cyber-crime/crimenetwork-returns-after-takedown-dismantled-again-by-german-authorities.html
Instructure confirms hackers used Canvas flaw to deface portals
https://www.bleepingcomputer.com/news/security/instructure-confirms-hackers-used-canvas-flaw-to-deface-portals/
Google Detects First AI-Generated Zero-Day Exploit - SecurityWeek
https://www.securityweek.com/google-detects-first-ai-generated-zero-day-exploit/
blackorbird on X: "#APT37 's GitHub repository overview https://t.co/STzpgfxfWR https://t.co/xWy2udlwj9" / X
https://x.com/blackorbird/status/1638357454097612805
SailPoint Discloses GitHub Repository Hack - SecurityWeek
https://www.securityweek.com/sailpoint-discloses-github-repository-hack/
Resurrected 'Crimenetwork' Marketplace Taken Down, Administrator Arrested - SecurityWeek
https://www.securityweek.com/resurrected-crimenetwork-marketplace-taken-down-administrator-arrested/
GitHub - AabyssZG/HashDump-BypassEDR: Windows绕过EDR实现DumpHash · GitHub
https://github.com/AabyssZG/HashDump-BypassEDR
New 'Dirty Frag' Linux Vulnerability Possibly Exploited in Attacks - SecurityWeek
https://www.securityweek.com/new-dirty-frag-linux-vulnerability-possibly-exploited-in-attacks/
Police shut down reboot of Crimenetwork marketplace, arrest admin
https://www.bleepingcomputer.com/news/security/police-shut-down-reboot-of-crimenetwork-marketplace-arrest-admin/
Checkmarx Jenkins AST Plugin Compromised in Supply Chain Attack - SecurityWeek
https://www.securityweek.com/checkmarx-jenkins-ast-plugin-compromised-in-supply-chain-attack/