LiteLLM Hack Exposes Secrets From 2,488 Companies Across 118,829 CI Runner Dumps
The LiteLLM supply-chain compromise has shifted from a short-lived malicious package incident into a sprawling enterprise exposure event. Analysis of an alle...
20 articles
The LiteLLM supply-chain compromise has shifted from a short-lived malicious package incident into a sprawling enterprise exposure event. Analysis of an alle...
A previously unseen Android near field communication (NFC) relay malware family dubbed WindRelay is being deployed in conjunction with a known remote access ...
WhatsApp has begun rolling out a new optional "Scam Alert" feature, which uses a local machine learning model to warn users when scammers are targeting them. [.
One expert called it a “pretty big shift in U.S.
Companies are used to thinking about attackers as outsiders trying to break in. North Korean IT workers flip that model.
The Israeli company has nearly $2 billion in total assets under management since 2014. The post Venture Firm Team8 Secures Additional $365 Million appeared f...
The U.S.
This essay was written with Nathan E. Sanders, and originally appeared in Tech Policy Press.
Wireshark has released version 4.6.
Armored Likho, also tracked as Eagle Werewolf, has expanded its espionage capability with a Rust-based toolkit that can hijack Telegram sessions and transfor...
The vulnerabilities could allow attackers to log in with random usernames and passwords or impersonate any FortiGate appliance. The post Fortinet Patches Aut...
Cloudflare has mitigated 23.2 million network-layer DDoS attacks and stopped 29.
Searchlight Cyber has launched its Preemptive Threat Exposure Management (PTEM) platform, combining exposure visibility with real-world attacker intelligence...
A massive 153GB archive stolen during the LiteLLM supply chain attack exposes credentials and other sensitive data linked to thousands of corporate domains, ...
A newly published internet-exposure analysis has identified more than 6,300 high-confidence industrial control system and building automation devices accessi...
Contracts may require a $1 million bond, which will be forfeited if a company fails to comply with operational requirements. The post White House Mobilizes S...
Huntress documents how a ransomware affiliate sabotaged its own attack with an anti-EDR effort
Tracked as CVE-2026–59310, the directory traversal bug allows remote attackers to execute arbitrary code. The post Critical VMware vCenter Vulnerability in A...
Dropped on Patch Tuesday, the exploit allows any user to spawn a shell with System privileges. The post Nightmare Eclipse Drops Windows Zero-Day Exploit ‘Shi...
Attackers are exploiting SharePoint flaw CVE-2026-55040 after a public PoC was released, allowing unauthenticated users to impersonate administrators. Attack...