ZeroHour

Search: “cloud credentials”

7 stories in the last 7d

Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example "sk-1234" Admin Key

Wiz found 294 of 3,074 internet-facing LiteLLM gateways accepted the documented default admin key sk-1234, exposing provider API keys and cloud IAM credentials.

Wiz Research's February Shodan scan found 3,074 LiteLLM gateways, 294 of which accepted the setup guide's sk-1234 admin key; 191 had no master key set and would accept any credential. The master key doubles as the authentication switch, and before 1.82.0-stable a gateway started without one granted every request full admin rights, exposing stored provider API keys, prompts, and MCP-connected tools. A documented pass-through endpoint lacks checks against private and cloud metadata addresses, letting an admin-key holder retrieve cloud IAM credentials, though no real-world abuse is reported. Related LiteLLM flaws include CVE-2026-59821 (disputed guardrail code execution), CVE-2026-59822 (CVSS 8.8, added to CISA KEV on September 2 and observed against Wiz honeypots), and CVE-2026-42271, used to install a cryptominer.

The Hacker Newsupdated · 6d agofirst · 6d agoVulnerability in the wild 3 sourcesCVE-2026-59821CVE-2026-59822CVE-2026-42271+2 CVEs

AWS Systems Manager Agent Vulnerability Allows Attackers to Bypass Port-Forwarding Restrictions

Critical SSRF flaw in AWS SSM Agent (CVE-2026-89049) lets authenticated users bypass link-local denylists and reach EC2 Instance Metadata Service for IAM credentials.

CVE-2026-89049 (Critical, CVSS v3.1 AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H) affects Amazon SSM Agent versions earlier than 3.3.4851.0, with the fix shipping in 3.3.4851.0. The remote-host port-forwarding feature's denylist for link-local addresses can be bypassed because equivalent address representations are not validated, enabling SSRF to restricted endpoints such as the EC2 Instance Metadata Service at 169.254.169.254. An attacker with authenticated AWS access and ssm:StartSession permission could retrieve instance profile IAM credentials and pivot to S3, Secrets Manager, Lambda, or other cloud resources depending on role permissions.

Critical WSO2 Vulnerability Allow Hackers to Gain Full Admin Access

WSO2 discloses CVE-2026-5430 (CVSS 10.0), an unauthenticated JWT authentication bypass allowing admin account takeover across its API management products.

WSO2 disclosed CVE-2026-5430, a critical authentication bypass (CVSS 10.0; 9.8 for single-tenant deployments) in advisory WSO2-2026-5328. The flaw stems from insecure JWT processing: tokens signed with unsupported algorithms bypass authentication checks, potentially granting unauthenticated attackers administrative access. Affected products include WSO2 API Control Plane 4.5.0-4.6.0, API Manager 4.1.0-4.6.0, Traffic Manager 4.5.0-4.6.0, and Universal Gateway 4.5.0-4.6.0. Fixes are available via update levels such as API Manager 4.6.0 update 21 or by migrating to unaffected releases.

Critical Dell ObjectScale Vulnerabilities Allows Malicious Users to Compromise the Affected system

Dell's DSA-2026-393 fixes ObjectScale/ECS flaws including unauthenticated deserialization RCE CVE-2026-70416 rated CVSS 10.0.

Dell advisory DSA-2026-393 (September 10, 2026) covers multiple flaws in ObjectScale and Elastic Cloud Storage (ECS). CVE-2026-70416 is a critical untrusted-data deserialization RCE (CVSS 10.0) in ObjectScale before 4.4.0.0 allowing unauthenticated remote code execution and full environment takeover, credited to researcher WinD39 (Huynh Dinh Vu). Additional issues include CVE-2025-43936 improper authentication (8.1), CVE-2026-26947 privilege management (6.7), CVE-2026-36591-style weak crypto CVE-2025-36591 (4.4), CVE-2026-76104 permission assignment DoS (5.5), plus third-party CVEs in Apache Log4j, liblzma, and the Linux kernel. Dell advises upgrading to version 4.4.0.0 or later (or 4.2.0.1) and restricting management interfaces until patched.

GitHub Pays $100,000 Bounty for Critical RCE Flaw in Git Push Pipeline

GitHub paid Saif Ghani $100,000 for CVE-2026-3854, a critical unauthenticated RCE in its Git push pipeline allowing command execution on backend infrastructure.

GitHub awarded researcher Saif Ghani $100,000, its largest publicly disclosed bug bounty, for CVE-2026-3854, a critical unauthenticated remote code execution flaw in its Git push processing pipeline. A crafted repository URL could trigger arbitrary command execution on backend infrastructure, threatening source code integrity, repository secrets, and software supply chains. GitHub deployed mitigations and completed a patch rollout through coordinated disclosure before technical details became public.

Cyber Security News · 2d agoVulnerabilityCVE-2026-38542

Critical Check Point Vulnerability Allows Remote Root Code Execution Without Authenticationnew

Check Point patched CVE-2026-91843 (CVSS 9.8), an unauthenticated stack overflow enabling remote root code execution on Security Management and Log Servers.

Check Point issued a high-severity alert for CVE-2026-91843, a critical stack overflow (CVSS 9.8, solution sk1000155) in the unauthenticated login workflow of Security Management Server, Multi-Domain Security Management Server, Log Server, and Multi-Domain Log Server. Successful exploitation grants an unauthenticated remote attacker root-level code execution. Affected releases span R80 through R82.20 with Jumbo Hotfix takes at or below specified levels (e.g., R82.20 Take 44, R81.20 Take 166), with several older versions end of support. A LivePatch is available and offline urgent bundles (R81.20-R82.20 Takes 28-29) were released; Smart-1 Cloud is already protected.

TP-Link Cameras 0-Day Vulnerabilities Allow Attackers to Spy on Users

Two zero-day flaws in TP-Link Tapo C200 cameras allowed authentication bypass and denial-of-service; fixed in firmware V5_1.4.6.

OPSWAT researchers Khoi Tran and Thai Do found CVE-2026-15315, an authentication bypass in the Tapo C200's local HTTPS interface that lets network-adjacent attackers replay an authentication value to gain administrator access, and CVE-2026-15316, an unauthenticated denial-of-service in the Wi-Fi onboarding process that crashes the camera's HTTPS service. TP-Link was notified on April 16, 2026, confirmed the flaws on July 10, and released patches on August 18, 2026 in firmware V5_1.4.6. Exploitation requires local network access but no valid account, existing session, or user interaction, exposing live feeds and stored recordings to surveillance risk.