Skip to main content

Share story

Security

Pwn2Own teams find 32 zero-day flaws, including exploits of Codex and LiteLLM

Pwn2Own teams find 32 zero-day flaws, including exploits of Codex and LiteLLM Image: Primary
Researchers found 32 previously undisclosed vulnerabilities on the first day of Pwn2Own Ireland on October 6, earning over $368,000 in prizes, Infosecurity Magazine reported. Targets included smartphones, smart home devices, printers and AI tools. Ikotas Labs exploited OpenAI Codex through argument injection. Taisic Yun of Xint combined improper input validation and code injection to obtain a reverse shell on LiteLLM. VinSOC used five zero-day flaws to exploit Oracle Autonomous AI Database. The Zero Day Initiative discloses findings to vendors, giving them 90 days to release updates before publication.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from Infosecurity Magazine and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Science Security
Science Security

Preprint finds sensitive-topic leakage in AI model routing logs

Researchers report in a preprint that logs recording which AI model handles a request can expose sensitive-topic patterns even when content logging is disabled. Their studies used 1.7 million real requests and tested systems that ...

Security AI
Security AI

Cloudflare opens early beta of AI-assisted security investigations

Cloudflare says an early beta of its multi-agent investigation system is available in Managed Defense for eligible application-security alerts and cases. The system assembles evidence, links related alerts and recommends next step...

Security Infrastructure
Security Infrastructure

IDCF Cloud ransomware attack disrupts companies and local governments

A ransomware attack disrupted IDCF Cloud's East Japan Region 1 on October 7, affecting websites and services used by companies and local governments. A note article citing ITmedia and Nikkei reports said unauthorized access began ...

Security AI
Security AI

AWS releases instructions for evidence-based AI vulnerability triage

AWS released a steering file that directs AI coding assistants to verify code paths before reporting vulnerabilities and to incorporate deployment controls into security priorities. The persistent instructions require confirmed fu...

Products Security
Products Security

Databricks makes user-scoped app authorization generally available

Databricks made on-behalf-of-user authorization generally available for apps that access supported platform APIs. Apps can now act with a signed-in user's identity, letting Unity Catalog enforce existing data permissions, row filt...