π΅οΈ RESEARCH & DEEP DIVES
-
LiteLLM flaw (CVE-2026-84377) lets authenticated users redirect proxy calls to steal provider credentials
An authenticated SSRF flaw in LiteLLM lets any proxy user redirect provider calls to attacker-controlled servers and exfiltrate the gateway's configured provider credentials.- Affects BerriAI LiteLLM proxy (AI gateway) versions prior to 1.88.6 and 1.96.2
- Any authenticated user can set routing parameters like api_base, base_url, model_list, fallbacks, and litellm_credential_name to redirect outbound provider calls
- The proxy then sends its stored provider credentials and configured secrets to the attacker's destination and can reach internal services (SSRF, CWE-918)
- Incomplete validation in auth_utils.py, common_request_processing.py, health/image endpoints, and litellm_pre_call_utils.py missed nested fields and bracket-notation form data
- CVSS 6.5 medium; fixed in versions 1.88.6 and 1.96.2 (GHSA-3cv6-jpf6-8222)
π Source: github.com Β· π Coverage: radar.offseq.com Β· π via CVE ThreatInt
-
Firefox for iOS Adds Built-In Ad and Tracker Blocking, No Extension Needed
Mozilla has added a built-in ad blocker to Firefox on iOS that blocks third-party ads and trackers without an extension.- Applies to Firefox users on iPhone (iOS).
- New built-in feature blocks many third-party advertisements and ad-related trackers.
- Aims to reduce visual clutter from pop-ups, overlays, and third-party ad scripts that slow browsing or interrupt reading.
- Works without downloading a separate browser extension.
π Coverage: cybersecuritynews.com Β· π via Cyber Security News
-
Shadow AI: Clients Adopting AI Tools Without Telling Their MSPs
Clients are adopting AI tools without informing their managed service providers.- Applies to managed service providers (MSPs) and their clients, whose technology environments MSPs are expected to fully understand.
- Shadow AI β client AI adoption kept outside MSP visibility β is increasingly driving critical technology decisions without the MSP's knowledge.
- MSPs normally track managed endpoints, business-critical applications, patching needs, sensitive data locations, and access β unreported AI use escapes that visibility.
π Coverage: securityboulevard.com Β· π via securityboulevard.com (discovered)
-
AI Agents Are Now Emailing Me with Their Security Concerns β <https://www.schneier.com/blog/archives/2026/09/ai-agents-are-now-emailing-me-with-their-security-concerns.html|Schneier on Security>
-
How the Hell Did an Island Suddenly Appear, Then Vanish? β <https://www.404media.co/how-the-hell-did-an-island-suddenly-appear-then-vanish/|404 Media>
-
The FCC wants consumers to rate their telecomβs anti-robocall protections β <https://cyberscoop.com/the-fcc-wants-consumers-to-rate-their-telecoms-anti-robocall-protections/|CyberScoop>
-
Dogged Russia-based botnet dismantled after 23-year run β <https://cyberscoop.com/sality-botnet-dismantled/|CyberScoop>
-
Fake Software Installers Disable Windows Update and Weaken Microsoft Defender β <https://thehackernews.com/2026/09/fake-software-installers-disable.html|The Hacker News>
-
Threat Gang 'Springs' Vishing Attacks on Microsoft Teams Users β <https://www.darkreading.com/cyberattacks-data-breaches/threat-gang-springs-vishing-attacks-microsoft-teams-users|Dark Reading>
-
Joro: Unauthenticated Cross-Origin Plugin Upload Leads to RCEJoro is a web ex... β <https://cve.threatint.com/CVE/CVE-2026-53649?utm_campaign=info&utm_medium=rss&utm_source=website|CVE ThreatInt>
-
DSpace: Remote Code Execution (RCE) possible in Velocity Templates used by LD... β <https://cve.threatint.com/CVE/CVE-2026-49832?utm_campaign=info&utm_medium=rss&utm_source=website|CVE ThreatInt>
-
DSpace: Path Traversal possible in LDN message generationDSpace open source s... β <https://cve.threatint.com/CVE/CVE-2026-49833?utm_campaign=info&utm_medium=rss&utm_source=website|CVE ThreatInt>
-
DSpace: Curation Task Reporter output path is not restricted to trusted direc... β <https://cve.threatint.com/CVE/CVE-2026-49831?utm_campaign=info&utm_medium=rss&utm_source=website|CVE ThreatInt>
-
DSpace: ORE resource URI does not validate scheme for non-web resourcesDSpace... β <https://cve.threatint.com/CVE/CVE-2026-49830?utm_campaign=info&utm_medium=rss&utm_source=website|CVE ThreatInt>
-
Nexus Repository 3 - Denial of Service via Unbounded Maven POM Metadata Field... β <https://cve.threatint.com/CVE/CVE-2026-77121?utm_campaign=info&utm_medium=rss&utm_source=website|CVE ThreatInt>
-
Nexus Repository 3 - Incorrect Authorization Allows Disclosure of Member Repo... β <https://cve.threatint.com/CVE/CVE-2026-77122?utm_campaign=info&utm_medium=rss&utm_source=website|CVE ThreatInt>
-
Nexus Repository 3 - Webhook Secret Disclosure via Capability Read APINexus R... β <https://cve.threatint.com/CVE/CVE-2026-77123?utm_campaign=info&utm_medium=rss&utm_source=website|CVE ThreatInt>
-
Nexus Repository 3 - Script Execution Disable Setting Not EnforcedIn affected... β <https://cve.threatint.com/CVE/CVE-2026-77124?utm_campaign=info&utm_medium=rss&utm_source=website|CVE ThreatInt>
-
Nexus Repository 3 - Incorrect Authorization on Blobstore Group EndpointsA vu... β <https://cve.threatint.com/CVE/CVE-2026-77125?utm_campaign=info&utm_medium=rss&utm_source=website|CVE ThreatInt>
-
ntegrals openbrowser Browser Agent Message Construction agent.ts resource con... β <https://cve.threatint.com/CVE/CVE-2026-84833?utm_campaign=info&utm_medium=rss&utm_source=website|CVE ThreatInt>
-
agentverus-scanner Companion Code Analysis Bypass via Excluded Python Bytecod... β <https://cve.threatint.com/CVE/CVE-2026-84811?utm_campaign=info&utm_medium=rss&utm_source=website|CVE ThreatInt>
-
claude-skill-antivirus Analysis Bypass via Manifest-Only Local Directory Scan... β <https://cve.threatint.com/CVE/CVE-2026-84810?utm_campaign=info&utm_medium=rss&utm_source=website|CVE ThreatInt>
-
Tencent AI-Infra-Guard skill-scan Analysis Bypass via Excluded Python Bytecod... β <https://cve.threatint.com/CVE/CVE-2026-84809?utm_campaign=info&utm_medium=rss&utm_source=website|CVE ThreatInt>
-
Open edX Platform: SSRF in Studio Video Download EndpointOpen edX Platform en... β <https://cve.threatint.com/CVE/CVE-2026-55421?utm_campaign=info&utm_medium=rss&utm_source=website|CVE ThreatInt>
-
Open edX LTI OAuth Replay AttackOpen edX Platform enables the authoring and d... β <https://cve.threatint.com/CVE/CVE-2026-53636?utm_campaign=info&utm_medium=rss&utm_source=website|CVE ThreatInt>
-
Open edX Platform: Insufficient Permission on set_course_mode_price()Open edX... β <https://cve.threatint.com/CVE/CVE-2026-53635?utm_campaign=info&utm_medium=rss&utm_source=website|CVE ThreatInt>
-
Nuclio: Unsanitized cron trigger event headers/body injected into CronJob she... β <https://cve.threatint.com/CVE/CVE-2026-52831?utm_campaign=info&utm_medium=rss&utm_source=website|CVE ThreatInt>
-
Nuclio: Unauthenticated OS command injection via namespace header in list-all... β <https://cve.threatint.com/CVE/CVE-2026-79756?utm_campaign=info&utm_medium=rss&utm_source=website|CVE ThreatInt>
-
Agentic security: Detection and response at machine speed β <https://aws.amazon.com/blogs/security/agentic-security-detection-and-response-at-machine-speed/|AWS Security Blog>
-
Revolut scam wave steals Β£180,000 from Jersey residents in just four weeks β <https://www.bitdefender.com/en-us/blog/hotforsecurity/revolut-scam-jersey|Graham Cluley>
-
Try reading that toot without throwing up challenge. β <https://cyberplace.social/@GossiTheDog/117202424348785772|@GossiTheDog@cyberplace.social>
-
MrBeast has signed a multi year overall deal to base his videos on using GenAI. β <https://cyberplace.social/@GossiTheDog/117202418865672335|@GossiTheDog@cyberplace.social>
-
WhatsApp Video Call Flaw Lets Anyone Bypass Your Android Lock Screen and View Your Photos β <https://cybersecuritynews.com/whatsapp-video-call-flaw/|Cyber Security News>
-
Google Launches Gemini 3.8 Flash Cyber to Identify and Auto-Patch Security Vulnerabilities β <https://cybersecuritynews.com/gemini-3-8-flash-cyber/|Cyber Security News>
-
KEV: CVE-2026-48710 β Kludex Starlette β Kludex Starlette HTTP Request/Response Smuggling Vulnerability β <https://nvd.nist.gov/vuln/detail/CVE-2026-48710|CISA KEV>
-
KEV: CVE-2026-49869 β Kestra Kestra OSS β Kestra OSS OS Command Injection Vulnerability β <https://nvd.nist.gov/vuln/detail/CVE-2026-49869|CISA KEV>
-
KEV: CVE-2026-59822 β BerriAI LiteLLM β BerriAI LiteLLM Improper Authentication Vulnerability β <https://nvd.nist.gov/vuln/detail/CVE-2026-59822|CISA KEV>
-
KEV: CVE-2026-82329 β JFrog Artifactory β JFrog Artifactory Improper Authentication Vulnerability β <https://nvd.nist.gov/vuln/detail/CVE-2026-82329|CISA KEV>
-
KEV: CVE-2026-83548 β SonicWall SMA1000 Appliances β SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability β <https://nvd.nist.gov/vuln/detail/CVE-2026-83548