Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Zero-Day Exploits Hit Microsoft Edge, Windows 11, and LiteLLM

Zero-Day Exploits Hit Microsoft Edge, Windows 11, and LiteLLM

Posted on May 15, 2026 By CWS

Pwn2Own Berlin 2026 commenced with a notable wave of zero-day exploits targeting leading browsers, operating systems, and AI advancements. On its opening day, cybersecurity experts succeeded in breaching Microsoft Edge, Windows 11, and LiteLLM, amassing $523,000 in rewards for unveiling 24 distinct vulnerabilities.

This event underscores the rising threat landscape where AI systems and central enterprise technologies are increasingly susceptible to intricate, chained cyberattacks.

Microsoft Edge Sandbox Breach

One of the most remarkable demonstrations was performed by Orange Tsai from the DEVCORE Research Team, who successfully carried out a sophisticated sandbox escape on Microsoft Edge. This exploit ingeniously combined four separate logic vulnerabilities, escalating minor defects into a complete system breach.

The intricate nature of this attack, which secured $175,000 and 17.5 Master of Pwn points, highlights how even fortified browser security can be compromised through a strategic combination of multiple weaknesses.

Windows 11 Security Challenges

Microsoft Windows 11 also emerged as a significant target, with multiple successful privilege escalation attacks reported throughout the day. Security researchers showcased several methods using heap-based buffer overflows and improper access control flaws to achieve heightened privileges.

These breaches demonstrate that even well-established operating systems remain vulnerable to memory corruption and access control issues, as evidenced by the persistent exploitation methods employed by participants like Angelboy and TwinkleStar03 of DEVCORE.

AI Platforms Under Siege

The scrutiny extended to AI infrastructures, with LiteLLM falling to a comprehensive exploit by researcher k3vg3n, who melded three vulnerabilities, including Server-Side Request Forgery (SSRF) and code injection, to achieve full system takeover.

This incident, which earned a $40,000 reward, underscores the critical security gaps that can arise in AI frameworks, particularly those handling external inputs and APIs, if not adequately fortified.

Other AI-focused targets were also compromised, with Compass Security exploiting OpenAI Codex through a CWE-150 flaw, and NVIDIA’s Megatron Bridge suffering breaches due to permissive allow lists and path-traversal vulnerabilities. IBM X-Force researchers further demonstrated the fragility of developer tools by exploiting a bug in the NV Container Toolkit.

Despite these successes, not all attempts succeeded, with some researchers unable to exploit certain targets like the OpenAI Codex within the allotted time. Additionally, numerous exploits relied on previously known vulnerabilities, highlighting the ongoing challenge of timely patching by organizations.

As Pwn2Own Berlin 2026 progresses, it becomes clear that the focus of attackers is shifting beyond traditional software to AI platforms, inference engines, and developer tools. With DEVCORE leading the charge, the event promises to reveal deeper vulnerabilities, serving as a critical alert to vendors and enterprises.

Cyber Security News Tags:AI platforms, AI security, Cybersecurity, DEVCORE, LiteLLM, Microsoft Edge, privilege escalation, Pwn2Own, sandbox escape, Windows 11, zero-day vulnerabilities

Post navigation

Previous Post: Hackers Exploit OAuth to Steal Microsoft 365 Credentials

Related Posts

Microsoft OAuth Device Phishing Threat Escalates Microsoft OAuth Device Phishing Threat Escalates Cyber Security News
BlueHammer Exploit Affects Windows Defender Security BlueHammer Exploit Affects Windows Defender Security Cyber Security News
MongoDB Servers at Critical Risk MongoDB Servers at Critical Risk Cyber Security News
Graphite Spyware Exploits Apple iOS Zero-Click Vulnerability to Attack Journalists Graphite Spyware Exploits Apple iOS Zero-Click Vulnerability to Attack Journalists Cyber Security News
New Magecart Attack Steals Customers Credit Cards from Website Checkout Pages New Magecart Attack Steals Customers Credit Cards from Website Checkout Pages Cyber Security News
Living Security Unveils HRMCon 2025 Speakers as Report Finds Firms Detect Just 19% of Human Risk Living Security Unveils HRMCon 2025 Speakers as Report Finds Firms Detect Just 19% of Human Risk Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Zero-Day Exploits Hit Microsoft Edge, Windows 11, and LiteLLM
  • Hackers Exploit OAuth to Steal Microsoft 365 Credentials
  • Shai-Hulud Malware Threatens Developer Ecosystems
  • Turla Develops Kazuar into Advanced P2P Botnet
  • Critical Flaws in OpenClaw AI Threaten 245,000 Servers

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Zero-Day Exploits Hit Microsoft Edge, Windows 11, and LiteLLM
  • Hackers Exploit OAuth to Steal Microsoft 365 Credentials
  • Shai-Hulud Malware Threatens Developer Ecosystems
  • Turla Develops Kazuar into Advanced P2P Botnet
  • Critical Flaws in OpenClaw AI Threaten 245,000 Servers

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark