Your AI Stack Just Handed Over Your Root Keys: Inside the litellm PyPI Breach
Malicious versions of the litellm Python package on PyPI are actively exfiltrating cloud credentials, SSH keys, and Kubernetes secrets from AI infrastructure.
Stories cluster related articles into a single narrative, linked to the underlying CVEs and affected products. 6,158 stories synthesized.
Malicious versions of the litellm Python package on PyPI are actively exfiltrating cloud credentials, SSH keys, and Kubernetes secrets from AI infrastructure.
GitLab released versions 18.10.1, 18.9.3, and 18.8.7 on March 25, 2026, fixing multiple high-severity vulnerabilities including a Jira Connect credential theft bug (CVE-2026-2370) and a CSRF flaw in the GLQL API (CVE-2026-3857).
The Silver Fox intrusion group has shifted tactics between 2025 and 2026, combining espionage-style operations with financially motivated cybercrime in three campaign waves targeting organizations across South and East Asia.
Citrix has released patches for two vulnerabilities in NetScaler ADC and Gateway, including a critical out-of-bounds read (CVE-2026-3055, CVSS 9.3) affecting SAML Identity Provider configurations.
ReversingLabs has uncovered a malicious npm campaign dubbed 'Ghost' that uses fake installation logs to conceal a remote access trojan targeting crypto wallets and sensitive data.
Apple released watchOS 26.4 (build 23T240) on March 24, 2026, addressing undisclosed security vulnerabilities in the Apple Watch operating system.
Apple released visionOS 26.4 on March 24, 2026, addressing undisclosed security vulnerabilities in the Apple Vision Pro headset.
Apple has released tvOS 26.4 (build 23L243) for Apple TV devices, addressing security vulnerabilities that could be exploited by attackers.
The FBI has officially tied the Handala hacking collective to Iran's Ministry of Intelligence and Security, revealing a multi-stage malware campaign targeting dissidents since autumn 2023.
The Zero Day Initiative has published a critical 0-day advisory for an unauthenticated command injection vulnerability in Microsoft Azure's azure-cli-mcp component, after Microsoft rated the flaw as Moderate and failed to patch it within the disclosure window.
The Tycoon2FA phishing kit has updated its tactics to include device-code phishing and the abuse of Trustifi click-tracking URLs to compromise Microsoft 365 accounts.
The cybercrime group TeamPCP has unleashed a self-propagating wiper worm, dubbed CanisterWorm, that destroys data on systems matching Iran's timezone or Farsi locale, spreading through exposed Docker APIs, exposed Docker APIs, Kubernetes clusters, and Redis servers.
The Trivy vulnerability scanner supply chain attack has escalated with two additional malicious Docker images, 0.69.5 and 0.69.6, both containing the TeamPCP infostealer, as Aqua Security confirms ongoing repository tampering.
Check Point's weekly threat intelligence report covers multiple breaches including Navia Benefit Solutions (2.6M affected) and Aura (900K records), plus critical vulnerabilities like CVE-2026-33017 in Langflow exploited within 20 hours of disclosure.
CISA has mandated that all U.S. federal civilian agencies patch CVE-2026-20131, a maximum-severity remote code execution vulnerability in Cisco Secure Firewall Management Center that the Interlock ransomware group has been exploiting as a zero-day since January.
A critical memory corruption vulnerability in Canon imageCLASS MF654Cdw printers, exploited at Pwn2Own, allows network-adjacent attackers to achieve remote code execution without authentication.
A cross-site scripting vulnerability in the Samsung Account app on the Galaxy S25, discovered at Pwn2Own, could let attackers execute arbitrary code via a malicious WebView.
A vulnerability in the Samsung Galaxy S25 Smart Touch Call application (CVE-2025-58488) could allow remote attackers to disclose stored credentials, requiring user interaction.
A vulnerability in the Samsung Account app redirect handling on the Samsung Galaxy S25 could allow attackers to launch arbitrary Android activities, discovered and disclosed through the Pwn2Own competition.
Threat actors weaponized a critical unauthenticated RCE vulnerability in the open-source Langflow framework within 20 hours of its advisory, using only the description to build exploits and harvest credentials.
The U.S. Justice Department, with Canadian and German authorities, dismantled four IoT botnets—Aisuru, Kimwolf, JackSkid, and Mossad—that compromised over three million devices and launched hundreds of thousands of DDoS attacks.
A 32-year-old buffer overflow in GNU inetutils Telnetd allows pre-authentication remote code execution, impacting Linux distributions, FreeBSD, NetBSD, Citrix NetScaler, and others.
A ransomware affiliate leak exposes the inner workings of a new ransomware group that splintered from Qilin, revealing advanced evasion techniques and internal tensions.
Zimperium zLabs reports a 56% increase in Android banking trojan attacks in 2025, with 1,243 financial brands targeted across 90 countries as malware families like TsarBot, CopyBara, and Hook dominate the threat landscape.