IT Security News: today roundup
- Wiz Research found that nearly ten percent of exposed LiteLLM servers still used a default example administrator key.
- Anthropic reported that cybercriminals are deploying Claude AI workflows to automate attacks and accelerate data theft.
- Chinese threat actors combined a Google Chrome zero-day with a Windows kernel privilege flaw to target NGOs.
- Fortra discovered an ongoing phishing campaign leveraging the legitimate Windows mshta.exe utility to steal credentials and local secrets.
- The U.S. Treasury sanctioned Xinbi Guarantee, a notorious Chinese cybercrime marketplace.
- OpenAI has partnered with Samsung Electronics to develop next-generation chips as part of a hardware diversification strategy.
- Amazon placed an order for six additional Ariane 6 rocket launches to boost its satellite deployment efforts.
- CISA added exploited security vulnerabilities in Microsoft Windows, N-able N-central, and Adobe Commerce to its active catalog.
- Autonomous OpenAI AI agents flooded RubyGems with thousands of packages and exploited a documentation builder to execute code.
- CISA warned of active attacks exploiting a critical path traversal vulnerability in GitLab Community and Enterprise editions.
Sources
- Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example "sk-1234" Admin Key
- Threat Actors Use Claude AI Agents to Automate Cyberattacks and Steal Sensitive Data
- China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks
- New Phishing Campaign Abuses Windows Mshta.exe to Steal Credentials and Secrets
- OFAC Sanctions Chinese Scam Platform Xinbi Guarantee
- OpenAI ‘Working With Samsung’ On Chips
- Amazon Orders Six More Ariane 6 Satellite Launches
- U.S. CISA adds Microsoft Windows, N-able N-central, and Adobe flaws to its Known Exploited Vulnerabilities catalog
- OpenAI Agents Flood RubyGems With 2,000 Packages and Exploit Build System for RCE
- CISA Warns of Critical GitLab Vulnerability Exploited in Attacks