⤷ Title: AI Interface Hijacked: Open WebUI Exploited for Cryptominers and Stealthy AI Malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Jun 2025 00:19:06 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Malware #AI #cryptomining #cybersecurity #Infostealer #LLM #malware #Open WebUI #Software Supply Chain #Sysdig #threat research
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 04 Jun 2025 00:19:06 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Malware #AI #cryptomining #cybersecurity #Infostealer #LLM #malware #Open WebUI #Software Supply Chain #Sysdig #threat research
Daily CyberSecurity
AI Interface Hijacked: Open WebUI Exploited for Cryptominers and Stealthy AI Malware
Sysdig uncovers a campaign exploiting misconfigured Open WebUI instances to deploy AI-assisted cryptominers and infostealers, showcasing new threat vectors.
⤷ Title: Next-Gen Malware: EtherRAT Uses Ethereum Smart Contract for Stealth C2
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 13 Dec 2025 10:38:12 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability #C2 #CVE_2025_55182 #cybersecurity #Ethereum #EtherRAT #Node.js #React2Shell #Remote Access Trojan #Smart Contract #Sysdig
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Sat, 13 Dec 2025 10:38:12 +0000
════════════════════════
⌗ Tags: #Malware #Vulnerability #C2 #CVE_2025_55182 #cybersecurity #Ethereum #EtherRAT #Node.js #React2Shell #Remote Access Trojan #Smart Contract #Sysdig
Penetration Testing Tools
Next-Gen Malware: EtherRAT Uses Ethereum Smart Contract for Stealth C2
The emergence of a new malicious tool within the React2Shell attack chain has become a notable development amid
⤷ Title: Exposed AWS Credentials Lead to AI-Assisted Cloud Breach in 8 Minutes
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 10:31:10 +0000
════════════════════════
⌗ Tags: #Security #Cyber Attacks #AI #AWS #Cloud security #Cyber Attack #Cybersecurity #security #Sysdig #Vulnerability
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Wed, 04 Feb 2026 10:31:10 +0000
════════════════════════
⌗ Tags: #Security #Cyber Attacks #AI #AWS #Cloud security #Cyber Attack #Cybersecurity #security #Sysdig #Vulnerability
Hackread
Exposed AWS Credentials Lead to AI-Assisted Cloud Breach in 8 Minutes
Exposed AWS Credentials enabled an AI-assisted cloud breach that escalated to full admin access in just 8 minutes, Sysdig researchers report.
⤷ Title: The 8-Minute Admin: How AI-Powered “LLMjacking” Crushed AWS Defenses in Record Time
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 09 Feb 2026 03:47:06 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI_assisted attack #Amazon Bedrock #AWS security #cloud breach 2026 #cybersecurity news #GPU resource abuse #IAM privilege escalation #LLMjacking #S3 bucket misconfiguration #Sysdig report
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 09 Feb 2026 03:47:06 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI_assisted attack #Amazon Bedrock #AWS security #cloud breach 2026 #cybersecurity news #GPU resource abuse #IAM privilege escalation #LLMjacking #S3 bucket misconfiguration #Sysdig report
Penetration Testing Tools
The 8-Minute Admin: How AI-Powered "LLMjacking" Crushed AWS Defenses in Record Time
An adversary successfully infiltrated an Amazon Web Services cloud environment, escalating to full administrative privileges in a mere
⤷ Title: Under 10 Hours: The marimo Terminal RCE Exploited in a Record-Breaking AI Sprint
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 13 Apr 2026 03:26:15 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI Exploitation #CVE_2026_39987 #cybersecurity #infosec #Marimo #Python #rce #Sysdig #threat intelligence #WebSocket Security
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 13 Apr 2026 03:26:15 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI Exploitation #CVE_2026_39987 #cybersecurity #infosec #Marimo #Python #rce #Sysdig #threat intelligence #WebSocket Security
Daily CyberSecurity
Under 10 Hours: The marimo Terminal RCE Exploited in a Record-Breaking AI Sprint
Unauthenticated RCE in marimo (CVE-2026-39987) exploited in the wild in record time. Attackers gained root access in under 10 hours. Patch to v0.23.0 now!
⤷ Title: CVE-2026-33626: High-Severity SSRF Exploited in the Wild to Hijack AI Inference Engines
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 02:37:27 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI security #Cloud Security #CVE_2026_33626 #Cyber Defense #IMDSv2 #InternVL2 #LLM Inference #LMDeploy #Qwen2_VL #Server_Side Request Forgery #ssrf #Sysdig TRT
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 02:37:27 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI security #Cloud Security #CVE_2026_33626 #Cyber Defense #IMDSv2 #InternVL2 #LLM Inference #LMDeploy #Qwen2_VL #Server_Side Request Forgery #ssrf #Sysdig TRT
Daily CyberSecurity
CVE-2026-33626: High-Severity SSRF Exploited in the Wild to Hijack AI Inference Engines
CVE-2026-33626: A critical SSRF in LMDeploy exploited in under 13 hours. Learn how attackers hijack AI nodes and how to secure your inference cloud now.
⤷ Title: Critical LiteLLM SQL Injection (CVE-2026-42208) Exploited in the Wild
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 01:53:32 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI security #CVE_2026_42208 #cybersecurity #Data Breach #Exploit #infosec #LiteLLM #Patch Alert #PostgreSQL #sql injection #Sysdig
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 28 Apr 2026 01:53:32 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI security #CVE_2026_42208 #cybersecurity #Data Breach #Exploit #infosec #LiteLLM #Patch Alert #PostgreSQL #sql injection #Sysdig
Daily CyberSecurity
Critical LiteLLM SQL Injection (CVE-2026-42208) Exploited in the Wild
LiteLLM CVE-2026-42208 is under active exploitation. Attackers are using SQL injection to steal AI credentials. Patch to v1.83.7 and rotate keys immediately.
⤷ Title: PraisonAI CVE-2026-44338 Exploited in the Wild Hours After Patch Disclosure
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 13 May 2026 02:00:36 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI security #Authentication Bypass #CVE_2026_44338 #Cyber Security #Exploit in the Wild #infosec #LLM Security #Multi_Agent Orchestration #PraisonAI #Sysdig TRT
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 13 May 2026 02:00:36 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI security #Authentication Bypass #CVE_2026_44338 #Cyber Security #Exploit in the Wild #infosec #LLM Security #Multi_Agent Orchestration #PraisonAI #Sysdig TRT
Daily CyberSecurity
PraisonAI CVE-2026-44338 Exploited in the Wild Hours After Patch Disclosure
Sysdig warns: PraisonAI (CVE-2026-44338) exploited in under 4 hours. Attackers bypassed auth to hijack agents and drain API quotas. Update to 4.6.34 now!
⤷ Title: Critical Pre-Auth Flaw CVE-2026-44338 Exploited to Hijack Autonomous AI Agents
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 18 May 2026 07:13:34 +0000
════════════════════════
⌗ Tags: #Vulnerability #AI Agent Hijacking #api_server.py #authentication bypass #Autonomous AI Security #CVE_2026_44338 #DevSecOps 2026 #LLM Token Abuse #Model Context Protocol #PraisonAI #Sysdig report
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Mon, 18 May 2026 07:13:34 +0000
════════════════════════
⌗ Tags: #Vulnerability #AI Agent Hijacking #api_server.py #authentication bypass #Autonomous AI Security #CVE_2026_44338 #DevSecOps 2026 #LLM Token Abuse #Model Context Protocol #PraisonAI #Sysdig report
Information Security News
Critical Pre-Auth Flaw CVE-2026-44338 Exploited to Hijack Autonomous AI Agents - Information Security News
Adversaries initiated a targeted reconnaissance campaign against vulnerable PraisonAI nodes less than four hours following the public disclosure of a critical security defect. An automated scanning entity identifying as CVE-Detector/1.0 launched offensives…
⤷ Title: SaaS-Style Cybercrime: Attackers Weaponize Langflow RCE and NATS Messaging for Ultra-Scalable C2
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 18 May 2026 08:06:31 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI Pipeline Security #CISA KEV #container escape #CVE_2026_33017 #Distributed Messaging #infosec #Langflow #NATS_as_C2 #Patch Alert #Remote Code Execution #Sysdig TRT
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 18 May 2026 08:06:31 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AI Pipeline Security #CISA KEV #container escape #CVE_2026_33017 #Distributed Messaging #infosec #Langflow #NATS_as_C2 #Patch Alert #Remote Code Execution #Sysdig TRT
Daily CyberSecurity
SaaS-Style Cybercrime: Attackers Weaponize Langflow RCE and NATS Messaging for Ultra-Scalable C2
Sysdig exposes "NATS-as-C2" infrastructure exploiting Langflow RCE (CVE-2026-33017). Learn how to defend your AI pipelines and block the exploit.
⤷ Title: NATS-as-C2: Critical Langflow Exploit Exploded to Fuel “LLMjacking” and Cloud Credential Theft
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 07:02:20 +0000
════════════════════════
⌗ Tags: #Vulnerability #AI Agent security #AWS Bedrock Exploitation #Cloud Credential Theft #CVE_2026_33017 #KeyHunter Botnet #Langflow Vulnerability #LLMjacking #NATS_as_C2 #Sysdig Threat Research #uTLS Fingerprinting
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 19 May 2026 07:02:20 +0000
════════════════════════
⌗ Tags: #Vulnerability #AI Agent security #AWS Bedrock Exploitation #Cloud Credential Theft #CVE_2026_33017 #KeyHunter Botnet #Langflow Vulnerability #LLMjacking #NATS_as_C2 #Sysdig Threat Research #uTLS Fingerprinting
Penetration Testing Tools
NATS-as-C2: Critical Langflow Exploit Exploded to Fuel "LLMjacking" and Cloud Credential Theft
Forensic specialists from Sysdig have intercepted an anomalous command architecture governing a malicious network, wherein the adversaries abandoned