Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: default-credentials (2 articles)Clear

Nearly one in ten exposed LiteLLM AI gateways still accept the example admin key

Researchers at Wiz found that nearly one in ten internet-facing LiteLLM servers still accept "sk-1234," the example administrator key printed in LiteLLM's own setup guide. LiteLLM is an open-source AI gateway that sits between an organization's apps and the model providers it pays for, and that admin key unlocks every stored provider API key; in Wiz's tests it even reached the cloud identity credentials of the host machine. The finding accompanies a cluster of exploited LiteLLM flaws that attackers have used to run code, steal secrets, and deploy crypto miners, with one ransomware group and a Microsoft-documented breach among them. Microsoft's advice is to treat AI gateways as top-tier secrets stores.

Check
Change the LiteLLM admin key immediately if it is still the default sk-1234, which needs no upgrade, and upgrade LiteLLM to 1.84.0 or later to close the exploited code-execution and auth-bypass flaws.
Affected
Organizations running internet-facing LiteLLM gateways, especially with the default admin key or on unpatched versions; an attacker can read every stored provider API key, reach cloud credentials, and sometimes execute code.
Fix
Replace default keys, patch to the latest LiteLLM, take gateways off the public internet, rotate all provider, cloud, and database credentials it can reach, and treat AI gateways as tier-zero secrets stores.

Exposed airline passenger database leaked 220 million records with passport data

Researchers found an exposed database holding more than 220 million airline passenger and crew records, including passport numbers and full flight itineraries, left reachable online. The data came from an Advance Passenger Information System, the kind airlines use to send traveler identity and passport details to border authorities, and it covered anyone who flew to, from, or through Vietnam between 2017 and 2026. Exposed fields included names, dates of birth, nationalities, passport numbers with issuing countries, and flight, seat, and baggage details. Researchers reached it by chaining misconfigurations and default credentials, and it was later secured, though whether the data was copied first is unknown because no access logs existed.

Check
Travelers who flew through the region should watch for identity theft and travel-themed phishing using real passport or itinerary details, and organizations holding traveler data should audit exposed databases and default credentials.
Affected
More than 220 million passenger and crew records with passport numbers, birth dates, nationalities, and flight itineraries were exposed; the data enables identity theft, document fraud, targeted phishing, and surveillance of travelers.
Fix
For organizations, inventory internet-facing databases, remove default credentials, require authentication and encryption on data stores, and enable access logging; aggregators of passport and travel data should treat exposure as high-impact risk.