threat-intel ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link A critical vulnerability, dubbed AgentForger, in OpenAI's ChatGPT Workspace Agents allowed a single phishing link to deploy a rogue AI agent within a victim's organization. The vulnerability, discovered by Zenity Labs, exploited a cross-site request forgery (CSRF) flaw, enabling an attacker to build and schedule an aut… The Hacker News · Jul 24, 2026 Critical CVE-2024-6587CVE-2026-40217CVE-2026-35029aiartificial intelligencephishing
threat-intel ⚡ Weekly Recap: Browser Bugs, EDR Killers, TV Botnet, OpenBSD Flaw, Android Trojan, and More This week’s cybersecurity news highlights a significant Fortinet vulnerability dubbed ‘FortiBleed,’ where over 80,000 FortiGate devices have been compromised by suspected Russian-speaking threat actors. Simultaneously, t… The Hacker News · Jun 22, 2026 Critical CVE-2026-24858CVE-2025-59718CVE-2025-59719RUcredential_reuseedrransomware
vulnerability LiteLLM Vulnerability Chain Lets Low-Privilege Users Take Over AI Gateway Servers A critical vulnerability chain in LiteLLM, an open-source AI gateway, allows low-privilege users to escalate their permissions to full administrator and execute arbitrary code on the server. Researchers at Obsidian Secur… The Hacker News · Jun 15, 2026 Critical CVE-2026-47101CVE-2026-47102CVE-2026-40217USaiproxyprivilege escalation