Stolen AI session tokens let thieves skip the login step

Okta found thousands of live AI session tokens in a stealer log, letting thieves replay their way into paid tools.

The Latest

Breaking News and Alerts

Wiz finds one in ten LiteLLM servers trust the sample admin key

Thousands of exposed AI gateways accept the demo key printed in LiteLLM's setup guide.

Spotlight

Cybersecurity Profiles and Stories

CISA gives agencies until Saturday to patch three exploited flaws

Three exploited networking flaws now carry a three-day federal patch deadline.

Brazil crime group Slim Spider drains wallets through cloud key theft

CrowdStrike details Slim Spider, a Brazil-based group stealing crypto custody secrets from financial clouds.

SAP patches CVSS 10 OVERPASS kernel bug reachable without credentials

SAP patches OVERPASS, a CVSS 10 kernel bug that lets unauthenticated attackers run commands on SAP hosts.

Planted prompt turned ChatGPT into a hidden Gmail relay

Check Point shows a planted instruction can make ChatGPT exfiltrate Gmail data through a covert channel between accounts.

Features

Research and Thought Leadership