AiRedTeam

漏洞分析

CVE-2026-42208 (CVSS 9.8) - LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) fo

🔥 热门漏洞情报 · NVD-Latest · 2026-05-08 CVE-2026-42208 (CVSS 9.8) - LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) fo Critical · CVSS 9.8 SQL注入 CVE-2026-42208 📋 漏洞概述 LiteLLM代理服务器在API密钥检查时存在SQL注入漏洞,未认证攻击者可利用特制Authorization头读取或修改数据库数据。 📋 基础信息 受影响版本LiteLLM >= 1.81.16, < 1.83.7 漏洞类型SQL注入 CVSS9.8 · Critical CVECVE-2026-42208 🔬 漏洞根因 在代理API密钥校验过程中,
阅读时间 3 分钟
安全情报

📊 2026-05-10 漏洞情报日报 · 200 条 · 高危 117

每日漏洞情报汇总 · 2026-05-10 📊 2026-05-10 漏洞情报日报 📋 共 200 条 🔥 高危/严重 117 条 🐙 GitHub-Advisory 59 条 🔥29 🛡️ NVD-Latest 88 条 🔥88 ⚔️ Sploitus 53 条 🤖 今日安全态势分析 🎯 今日重点关注 * CVE-2026-33587 (CVSS 10.0) - Open Notebook v1.8.3:服务器端模板注入(SSTI)漏洞,导致远程代码执行。攻击者可利用未经验证的用户输入直接执行Python代码及系统命令,需立即修补。 * CVE-2026-8153 (CVSS 9.8) - Universal Robots PolyScope:Dashboard Server接口存在操作系统命令注入漏洞,
阅读时间 25 分钟
漏洞分析

[local] Windows 11 24H2 - Local Privilege Escalation

CVE-2026-21250 Windows HTTP.sys驱动在处理特制HTTP请求时存在空指针解引用漏洞,可导致本地拒绝服务(BSOD)或任意代码执行。 High · CVSS 7.8 (估计基于本地权限提升场景) 📋 漏洞基础信息 CVECVE-2026-21250漏洞类型空指针解引用 / 未验证的用户指针传递受影响版本Windows 11 24H2 (10.0.26100.7780), Windows 11 25H2 (10.0.26200.7780), Windows Server 2022 23H2 (10.0.25398.2148)危害等级High · CVSS 7.8 (估计基于本地权限提升场景)发布日期2026-05-04提交者London foggy snow来源Exploit-DB 原文 ↗ 🔬 漏洞根因 CVE-2026-21250的触发依赖于向HTTP.sys驱动传递一个二进制恶意指针(X-Trigger-Ptr头),该指针包含空字节(
阅读时间 13 分钟
安全情报

&#x5b;Guest Diary&#x5d; Beyond Cryptojacking: Telegram tdata as a Credential Harvesting Vector, Lessons from a Honeypot Incident, (Wed, Apr 22nd)

📡 SANS ISC · 2026-04-22 &#x5b;Guest Diary&#x5d; Beyond Cryptojacking: Telegram tdata as a Credential Harvesting Vector, Lessons from a Honeypot Incident, (Wed, Apr 22nd) [Guest Diary] Beyond Cryptojacking: Telegram tdata as a Credential Harvesting Vector, Lessons from a Honeypot Incident Published: 2026-04-22. Last Updated: 2026-04-22 00:03:04
阅读时间 4 分钟
安全情报

Can AI Attack the Cloud? Lessons From Building an Autonomous Cloud Offensive Multi-Agent System

📡 Palo Alto Unit42 · 2026-04-23 Can AI Attack the Cloud? Lessons From Building an Autonomous Cloud Offensive Multi-Agent System Executive Summary The offensive capabilities of large language models (LLMs) have until recently existed as theoretical risks – frequently discussed at security conferences and in conceptual industry reports, but rarely discovered in practical
阅读时间 4 分钟
[!] CONTACT_CHANNELS

如需商务合作、技术咨询或漏洞反馈,请通过以下离岸节点联系作者。

> PING_AUTHOR (@A1RedTeam)