https://chocapikk.com/posts/2026/lightllm-pickle-rce/
Интересная 0-day уязвимость в LightLLM, на которую не обращают внимания уже давно команда поддерживающая данный проект. Год назад им подсветили в ишуях про одну уязвимость связанную с работой через WebSocket, которую они долго игнорировали, а тут Валентин обнаружил другую. Так что почитайте то что описано и примите к сведению либо воспользуйтесь одним из трех способов, которые описаны в статье под частью "Suggested Fix"
Интересная 0-day уязвимость в LightLLM, на которую не обращают внимания уже давно команда поддерживающая данный проект. Год назад им подсветили в ишуях про одну уязвимость связанную с работой через WebSocket, которую они долго игнорировали, а тут Валентин обнаружил другую. Так что почитайте то что описано и примите к сведению либо воспользуйтесь одним из трех способов, которые описаны в статье под частью "Suggested Fix"
Chocapikk
LightLLM: Unauthenticated RCE via Pickle Deserialization in WebSocket Endpoints - Chocapikk's Cybersecurity Blog
CVE-2026-26220: A critical unauthenticated RCE vulnerability in LightLLM's PD disaggregation system. Two WebSocket endpoints deserialize binary frames with pickle.loads() without authentication, and the server explicitly refuses to bind to localhost - it's…
Keygraph - Shannon
Fully autonomous AI pentester to find actual exploits in your web apps.
Shannon has achieved a 96.15% success rate on the hint-free, source-aware XBOW Benchmark
Fully autonomous AI pentester to find actual exploits in your web apps.
Shannon has achieved a 96.15% success rate on the hint-free, source-aware XBOW Benchmark
GitHub
GitHub - KeygraphHQ/shannon: Shannon is an AI pentester for web applications and APIs. It analyzes your source code, identifies…
Shannon is an AI pentester for web applications and APIs. It analyzes your source code, identifies attack vectors, and executes real exploits to prove vulnerabilities before they reach production. ...
Forwarded from Около DevOps
В экосистеме Trivy обнаружена новая крупная атака: злоумышленники скомпрометировали GitHub Actions, массово обновив теги и подменив код на вредоносный. Теперь при запуске Trivy в CI/CD вор может похитить секреты, ключи и креды облаков, а также токены Kubernetes. Рекомендуется срочно перейти на версию 0.35.0 либо зафиксированный SHA.
Socket
Trivy Under Attack Again: Widespread GitHub Actions Tag Comp...
Attackers compromised Trivy GitHub Actions by force-updating tags to deliver malware, exposing CI/CD secrets across affected pipelines.
https://futuresearch.ai/blog/litellm-pypi-supply-chain-attack/
Очередная атака связанная с получением доступа к гитхаб аккаунту owner'а litellm, в которой не только выпустили скомпроментированные версии, но также и закрыли ишую, в которой была описана проблема безопасности. Попадая на вашу систему python скрипт рассылает на определенный домен приватные ключи, .env файлы, ключи от AWS/GCP/Azure, kubeconfig'и пароли к базам, шелл историю, а также енв переменные и всякое другое до чего может дотянуться. Так что будьте аккуратны и проверьте если у вас используется где-то litellm версии 1.82.8 или 1.82.7
Очередная атака связанная с получением доступа к гитхаб аккаунту owner'а litellm, в которой не только выпустили скомпроментированные версии, но также и закрыли ишую, в которой была описана проблема безопасности. Попадая на вашу систему python скрипт рассылает на определенный домен приватные ключи, .env файлы, ключи от AWS/GCP/Azure, kubeconfig'и пароли к базам, шелл историю, а также енв переменные и всякое другое до чего может дотянуться. Так что будьте аккуратны и проверьте если у вас используется где-то litellm версии 1.82.8 или 1.82.7
FutureSearch
litellm 1.82.8 Supply Chain Attack on PyPI (March 2026)
litellm 1.82.7 and 1.82.8 on PyPI were compromised in March 2026 with a malicious .pth file that steals SSH keys, cloud credentials, and secrets, then spreads across Kubernetes clusters. FutureSearch first reported it to PyPI. Learn which versions to avoid…
Forwarded from Около DevOps
X (formerly Twitter)
International Cyber Digest (@IntCyberDigest) on X
🚨‼️ We're in contact with the actor behind the Trivy and LiteLLM hack. They told us they are currently extorting several multi-billion-dollar companies from which they've exfiltrated data.
They've obtained 300 GB of compressed credentials and are working…
They've obtained 300 GB of compressed credentials and are working…
OWASP выпустил еще в декабре новый фреймворк top10 по агентам OWASP Top 10 for Agentic Applications for 2026
OWASP Gen AI Security Project
OWASP Top 10 for Agentic Applications for 2026
The OWASP Top 10 for Agentic Applications 2026 is a globally peer-reviewed framework that identifies the most critical security risks facing autonomous and agentic AI systems. Developed through extensive collaboration with more than 100 industry experts,…
Forwarded from white2hack 📚
Cyber Security Attack Mindmap 🔥
Cyber Attacks focus on identifying vulnerabilities, exploiting systems, and maintaining access during offensive security operations.
This mindmap provides a structured breakdown of real-world attack techniques, tools, and methodologies used by attackers and red teamers.
Topics Covered in the Mindmap:
🔍 Reconnaissance
⚔️ Initial Access
💥 Exploitation
🎯 Privilege Escalation
🕵️ Lateral Movement
📦 Credential Dumping
🔐 Persistence
🚫 Defense Evasion
📡 Command & Control
#pentest
Cyber Attacks focus on identifying vulnerabilities, exploiting systems, and maintaining access during offensive security operations.
This mindmap provides a structured breakdown of real-world attack techniques, tools, and methodologies used by attackers and red teamers.
Topics Covered in the Mindmap:
🔍 Reconnaissance
⚔️ Initial Access
💥 Exploitation
🎯 Privilege Escalation
🕵️ Lateral Movement
📦 Credential Dumping
🔐 Persistence
🚫 Defense Evasion
📡 Command & Control
#pentest
Forwarded from white2hack 📚
Cyber Security Attack Mindmap.pdf
182.6 KB
Cyber Security Attack Mindmap 🔥
Forwarded from Около DevOps
Интересный разбор атаки ForceMemo, читаешь как детектив
https://www.stepsecurity.io/blog/forcememo-hundreds-of-github-python-repos-compromised-via-account-takeover-and-force-push
Насколько многогранно люди подходят к планированию подобных атак, прямо диву даешься
https://www.stepsecurity.io/blog/forcememo-hundreds-of-github-python-repos-compromised-via-account-takeover-and-force-push
Насколько многогранно люди подходят к планированию подобных атак, прямо диву даешься
www.stepsecurity.io
ForceMemo: Hundreds of GitHub Python Repos Compromised via Account Takeover and Force-Push - StepSecurity
The StepSecurity threat intelligence team was the first to discover and report on an ongoing campaign — which we are tracking as ForceMemo — in which an attacker is compromising hundreds of GitHub accounts and injecting identical malware into hundreds of…