Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Zero-Day Exploits Hit Microsoft Edge, Windows 11, and LiteLLM

Zero-Day Exploits Hit Microsoft Edge, Windows 11, and LiteLLM

Posted on May 15, 2026 By CWS

Pwn2Own Berlin 2026 commenced with a notable wave of zero-day exploits targeting leading browsers, operating systems, and AI advancements. On its opening day, cybersecurity experts succeeded in breaching Microsoft Edge, Windows 11, and LiteLLM, amassing $523,000 in rewards for unveiling 24 distinct vulnerabilities.

This event underscores the rising threat landscape where AI systems and central enterprise technologies are increasingly susceptible to intricate, chained cyberattacks.

Microsoft Edge Sandbox Breach

One of the most remarkable demonstrations was performed by Orange Tsai from the DEVCORE Research Team, who successfully carried out a sophisticated sandbox escape on Microsoft Edge. This exploit ingeniously combined four separate logic vulnerabilities, escalating minor defects into a complete system breach.

The intricate nature of this attack, which secured $175,000 and 17.5 Master of Pwn points, highlights how even fortified browser security can be compromised through a strategic combination of multiple weaknesses.

Windows 11 Security Challenges

Microsoft Windows 11 also emerged as a significant target, with multiple successful privilege escalation attacks reported throughout the day. Security researchers showcased several methods using heap-based buffer overflows and improper access control flaws to achieve heightened privileges.

These breaches demonstrate that even well-established operating systems remain vulnerable to memory corruption and access control issues, as evidenced by the persistent exploitation methods employed by participants like Angelboy and TwinkleStar03 of DEVCORE.

AI Platforms Under Siege

The scrutiny extended to AI infrastructures, with LiteLLM falling to a comprehensive exploit by researcher k3vg3n, who melded three vulnerabilities, including Server-Side Request Forgery (SSRF) and code injection, to achieve full system takeover.

This incident, which earned a $40,000 reward, underscores the critical security gaps that can arise in AI frameworks, particularly those handling external inputs and APIs, if not adequately fortified.

Other AI-focused targets were also compromised, with Compass Security exploiting OpenAI Codex through a CWE-150 flaw, and NVIDIA’s Megatron Bridge suffering breaches due to permissive allow lists and path-traversal vulnerabilities. IBM X-Force researchers further demonstrated the fragility of developer tools by exploiting a bug in the NV Container Toolkit.

Despite these successes, not all attempts succeeded, with some researchers unable to exploit certain targets like the OpenAI Codex within the allotted time. Additionally, numerous exploits relied on previously known vulnerabilities, highlighting the ongoing challenge of timely patching by organizations.

As Pwn2Own Berlin 2026 progresses, it becomes clear that the focus of attackers is shifting beyond traditional software to AI platforms, inference engines, and developer tools. With DEVCORE leading the charge, the event promises to reveal deeper vulnerabilities, serving as a critical alert to vendors and enterprises.

Cyber Security News Tags:AI platforms, AI security, Cybersecurity, DEVCORE, LiteLLM, Microsoft Edge, privilege escalation, Pwn2Own, sandbox escape, Windows 11, zero-day vulnerabilities

Post navigation

Previous Post: Hackers Exploit OAuth to Steal Microsoft 365 Credentials
Next Post: Tycoon 2FA Phishing Kit Exploits OAuth for Account Breaches

Related Posts

AWS Lambda Vulnerability Risks Unauthorized Cloud Access AWS Lambda Vulnerability Risks Unauthorized Cloud Access Cyber Security News
Misconfigurations in Docker and Kubernetes Pose Security Risks Misconfigurations in Docker and Kubernetes Pose Security Risks Cyber Security News
CISA Details 17 Hacker Tactics Targeting Active Directory CISA Details 17 Hacker Tactics Targeting Active Directory Cyber Security News
Microsoft Launches Project Zenith for Local AI Model Execution Microsoft Launches Project Zenith for Local AI Model Execution Cyber Security News
Malicious Chrome Extension Targets Crypto Wallets Malicious Chrome Extension Targets Crypto Wallets Cyber Security News
Thai College Website Hack Exploited for Illegal Casino Ads Thai College Website Hack Exploited for Illegal Casino Ads Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Tech Leaders Agree to Self-Regulate on AI Development
  • Cybercriminals Exploit ChatGPT for Malware Distribution
  • GitHub AI Uncovers 24 Security Flaws in Android Apps
  • AI Model GPT-6 Astra Raises Security Concerns in Simulations
  • OpenAI Cancels GPT-6.1 Astra Due to Security Issues

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Tech Leaders Agree to Self-Regulate on AI Development
  • Cybercriminals Exploit ChatGPT for Malware Distribution
  • GitHub AI Uncovers 24 Security Flaws in Android Apps
  • AI Model GPT-6 Astra Raises Security Concerns in Simulations
  • OpenAI Cancels GPT-6.1 Astra Due to Security Issues

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark