Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example “sk-1234” Admin Key

A Shocking Weakness in LiteLLM Gateways Exposes Thousands of Organizations to Cyber Threats A concerning discovery has been made regarding the security of LiteLLM gateways, a crucial component of many organizations’ infrastructure. It appears that nearly 1 in 10 exposed LiteLLM gateways are vulnerable to unauthorized access due to an easily guessable admin key. The … Read more

CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline

Cybersecurity authorities have issued a stark warning, highlighting the urgent need for patching three critical vulnerabilities in widely used network security products. The US Cybersecurity and Infrastructure Security Agency (CISA) has flagged exploited flaws in Cisco, Citrix, and Fortinet systems, setting a federal deadline of September 12 for affected organizations to apply patches. The problem … Read more

Trezor warns users of email provider breach, phishing attacks

Cryptocurrency wallet maker Trezor is warning its users of a phishing attack that appears to be linked to a recent breach of its email provider. The company has confirmed that threat actors have been sending fake “critical security alert” emails to affected customers, claiming that their hardware wallets are vulnerable to hacking due to a … Read more

Microsoft fixes bug that wiped Windows desktop settings

**Critical Bug Fixed: Microsoft Resolves Issue Causing Lost Desktop Settings** In a major relief for millions of Windows users, Microsoft has finally addressed a critical bug that was causing desktop settings to be lost or reset on some devices. The issue, which surfaced after the installation of the KB5120998 August 2026 preview update, had been … Read more

CISA: WatchGuard RCE flaw now exploited in ransomware attacks

A Critical WatchGuard Flaw Now Being Exploited by Ransomware Gangs The US Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs have started using a previously identified vulnerability in WatchGuard Firebox firewalls to carry out attacks. This critical flaw, tracked as CVE-2025-14733, was first flagged by CISA in December 2025 and allows unauthenticated … Read more

Anthropic Discloses Fourth AI Hacking Incident Involving Claude Opus 4.6

A Fourth AI Hacking Incident Rocks Anthropic’s Claude Platform, Leaving Users Vulnerable to Data Theft and Exploitation The latest security incident to hit AI giant Anthropic has left users of its popular Claude platform scrambling for answers. For the fourth time this year, hackers have successfully breached the system, compromising sensitive information and potentially exposing … Read more

Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example “sk-1234” Admin Key

Exposure of LiteLLM Gateways Leaves Thousands Vulnerable to Ransomware and Data Theft A recent investigation has uncovered a disturbing trend in the world of cybersecurity, with nearly 1 in 10 exposed LiteLLM gateways accepting a default administrator key. This administrative backdoor was created by researchers as an example, but it seems some unwitting administrators took … Read more

Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks

A Critical Vulnerability in Fortinet Products is Being Exploited to Deploy a Powerful Backdoor Threat actors have been exploiting an unauthenticated remote code execution (RCE) vulnerability in Fortinet products to deploy a powerful backdoor, known as PivotC2 RAT. This high-severity bug was patched by Fortinet in January, but it appears that some organizations are still … Read more

New ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft Defender

Microsoft’s Windows Defender is once again at the center of a cybersecurity storm, courtesy of a new zero-day exploit dubbed ShieldCrash. This latest vulnerability, discovered by security researcher Nightmare Eclipse, targets fully patched Windows systems and allows attackers to gain full System privileges. The proof-of-concept (PoC) code released by Nightmare Eclipse demonstrates an arbitrary file … Read more

EU Cyber Resilience Act to Enforce New Reporting Requirements

The European Union has taken a significant step towards enhancing cyber resilience in its member countries with the introduction of the Cyber Resilience Act (CRA). Starting September 11, businesses operating in the EU will be required to report serious product security incidents within 24 hours, or face hefty penalties. This move marks a major shift … Read more