🚨CVE ALERT!
While working with Nuclei @wiz_io, I discovered CVE-2024-43405, a vulnerability that bypasses template signature verification, potentially allowing malicious code execution on machines running Nuclei 🛡️
Here’s what you need to know: 🧵
All those "thank you" comments piling up on the litellm issue?
The attackers are using the victims' stolen GitHub credentials to post them. They are literally thanking themselves using compromised accounts 🤯
https://t.co/RGKJ0fQxrY
Everyone using litellm as their LLM gateway/proxy: double-check your installs
Official GitHub security report (opened today):
https://t.co/RGKJ0fQxrY
This is why supply-chain security matters. Spread the word so no one loses their keys.
🚨 CRITICAL SECURITY ALERT: A major supply chain attack has been discovered in the litellm Python package.
Version 1.82.8 on PyPI contains a highly aggressive credential-stealer. If you or your team installed this version, assume your secrets are compromised. 🧵👇
⚠️ WHAT TO DO RIGHT NOW:
1️⃣ Check your environments and CI/CD pipelines for litellm==1.82.8.
2️⃣ Look for litellm_init.pth in your Python site-packages/ directory.
3️⃣ If you installed this version, ROTATE ALL SECRETS, SSH keys, and cloud credentials immediately.
What started as a big "what if" a few months ago is finally live
We took years of offensive security expertise and built an AI that actually thinks like a hacker. So proud to have built this from the ground up alongside @galnagli and a brilliant team! 👇
✨ Today we're launching the Wiz Red Agent -- an AI-powered attacker that finds vulnerabilities by reasoning about your apps the way a world-class pentester would, but continuously, across your entire attack surface.
Our recent research reveals how malware-less database ransomware actually scales ⚡️
Finding: MongoDB is the most dominant target, and a newly exposed DB can be discovered and hijacked within minutes - without dropping a single binary. 👾 (1/5)🧵
Introducing Multiverse: the first AI-generated multiplayer game.
Multiplayer was the missing piece in AI-generated worlds — now it’s here. Players can interact and shape a shared AI-simulated world, in real-time.
Training and research cost < $1.5K. Run it on your own PC.
We @enigma_ai are open-sourcing everything: code, data, weights, architecture, and research.
Here’s a closer look (and how it works!):