Pwn2Own Researchers Exploit Codex and LiteLLM as LLM Safety Checks Are Bypassed

Summary
This cybersecurity roundup covers Pwn2Own exploits against Codex and LiteLLM, research on bypassing LLM safety checks, active exploitation of several vulnerabilities, a Zammad breach, and security industry developments.
Key points
- Pwn2Own Ireland’s opening day featured 32 zero-days and $388,500 in awards, including exploits against OpenAI Codex, LiteLLM, and Oracle Autonomous AI Database.
- CrowdStrike researchers bypassed an LLM safety classifier by splitting offensive code requests into smaller, seemingly ordinary tasks; the method worked in nine of 10 tested categories.
- DIVD confirmed volunteer email addresses were stolen in a Zammad breach involving remote code execution and privilege-escalation flaws; the operator and model remain unidentified.
- Attackers are exploiting flaws in NetScaler, FortiMail, and Cisco SD-WAN; vendors have issued advisories and patches or mitigations.
- GitLab patched an AI Gateway sandbox escape that could let an authorized user execute code on a self-hosted gateway.
- Datadog observed scripts testing exposed AWS keys for access to models through Amazon Bedrock, with similar malicious activity seen at 12 organizations over 30 days.
Article Details
- Event Type
- Weekly cybersecurity news roundup covering vulnerability exploitation, security research, product updates, and cybersecurity funding.
- Impact
- Reported impacts include stolen volunteer email addresses in the Zammad breach; active exploitation of vulnerabilities affecting NetScaler, FortiMail, and Cisco SD-WAN Manager; and potential unauthorized access to AI models using exposed AWS credentials. Remote code execution through the NetScaler flaw was not confirmed. Other findings describe demonstrated exploits, patches, research results, and product or funding announcements.
CVE
CVE-2026-104286Fortinet says attackers are exploiting CVE-2026-104286, a CVSS 9.8 flaw in FortiMail’s Identity Based Encryption interface. It lets an attacker write files to the system without signing in, potentially leading to codeCVE-2026-76504Cisco confirms exploitation of CVE-2026-76504, which lets unauthenticated attackers reach administrative SD-WAN Manager APIs through crafted requests.CVE-2026-88779Attackers are exploiting CVE-2026-88779 in customer-managed NetScaler ADC and Gateway systems configured as a SAML service provider or identity provider. The memory-overflow flaw can crash the service. Remote codeCVE-2026-90970GitLab fixed CVE-2026-90970 in its AI Gateway. A signed-in user with Duo Agent Platform access could use a custom-flow prompt template to break out of its sandbox and execute code on a self-hosted gateway.
People
Vendors
AmazonI hope you’re having an excellent week! It’s been a very, very long one for me as I’m currently refreshing the AI Tooling Visibility book and getting it ready for Amazon storefront. More on that soon!AppleApple plans tighter Full Disk Access controlsCiscoCisco patches another SD-WAN authentication bypassCrowdStrikeCrowdStrike bypasses LLM safety checks by splitting up requestsDatadogCybersecurity Pulse (TCP)! I’m Darwin Salazar, Head of Growth at Monad and former detection engineer at Datadog. Each week, I bring you the latest security innovation and industry news. Subscribe to receive weeklyFortinetFortinet says attackers are exploiting CVE-2026-104286, a CVSS 9.8 flaw in FortiMail’s Identity Based Encryption interface. It lets an attacker write files to the system without signing in, potentially leading to codeGitLabGitLab patches an AI Gateway sandbox escapeGoogle📬 Google pauses part of its open-source bounty: New product-vulnerability submissions stopped after a flood of mostly invalid automated reports.Legit SecurityLegit Security expanded its remediation agent to vulnerable dependencies.Microsoftstill blocked. The classifier screened each request separately and never saw the completed attack code. Microsoft’s separate capability-laundering study describes a related pattern.MistralGoogle and Mistral expand access for cyber defendersWizWiz launches AI code scanning with cloud context
Products
Amazon Bedrock🧾 Attackers test stolen AWS keys: Datadog shows how attackers check whether stolen credentials let them use AI models through Amazon Bedrock.Cisco SD-WAN ManagerCodex🏆 Pwn2Own hits AI infrastructure: Day one brought 32 zero-days, with wins against Codex, LiteLLM, and Oracle’s AI database.ContinuumAWS says Continuum for code vulnerabilities completed 819 of 920 CyberGym-E2E tasks (89%) within 90 minutes each. To pass, it had to find a bug, demonstrate it, and produce a patch that kept the project’s tests passing.CyberGym-E2ECyberGym-E2E’s workflow for evaluating discovery and repair. Source: CyberGym-E2E authors.Duo Agent PlatformGitLab fixed CVE-2026-90970 in its AI Gateway. A signed-in user with Duo Agent Platform access could use a custom-flow prompt template to break out of its sandbox and execute code on a self-hosted gateway.FortiMailFortiMail’s encryption interface is under attackGemini 4 ArgonGoogle began rolling out Gemini 4 Argon to trusted defenders through Fairwind, promising access without cyber guardrails for those partners and its internal teams. Broader availability is still ahead.GitLab AI GatewayLiteLLM🏆 Pwn2Own hits AI infrastructure: Day one brought 32 zero-days, with wins against Codex, LiteLLM, and Oracle’s AI database.macOSApple announced additional macOS controls that will require more explicit user action before granting Full Disk Access.Mistral Large 4NetScaler ADCAttackers are exploiting CVE-2026-88779 in customer-managed NetScaler ADC and Gateway systems configured as a SAML service provider or identity provider. The memory-overflow flaw can crash the service. Remote codeNetScaler GatewayOracle Autonomous AI DatabaseA second LiteLLM exploit used four bugs, two of them previously known, and earned Out of Bounds $15,000. VinSOC also combined five bugs against Oracle Autonomous AI Database for a $40,000 win.Wiz AI SASTWiz AI SAST is in public preview for Wiz Code customers. The scanner uses AI to find business-logic flaws, including missing ownership checks that let one user read another’s data. The Wiz Security Graph links findingsZammadDIVD details its Zammad breach