AI Security Proxy Fails Open
An AI proxy built to secure your systems just defaulted to wide open. Here is how hackers are targeting centralized API keys.
What the video says
an AI proxy built for security, just defaulted to open. On September 2nd, CISA added LiteLLM's bypass to its Active Exploit Catalog.
This is the third LiteLLM vulnerability added to the catalog in 4 months. Wiz discovered active exploitation targeting these proxies because they concentrate sensitive API keys.
When LiteLLM validation failed, the code defaulted to an open OAuth2 fallback, returning empty, unrestricted API key objects.