Federal agencies face urgent remediation deadlines as CISA confirms active exploitation of CVE-2023-49105, allowing attackers to access and delete cloud storage files without credentials.
Vulnerability researchers observe mass automated scanning and exploitation of Langflow AI visual frameworks, exfiltrating OpenAI and AWS secrets while deploying botnets.
Wiz Research discovered that 10% of internet-facing LiteLLM AI proxy gateways accepted the default documentation admin key sk-1234, leaking upstream model keys and cloud IAM tokens.