Over 95% of the affected companies were exposed before the malicious LiteLLM packages were published.
Hi, what are you looking for?
Over 95% of the affected companies were exposed before the malicious LiteLLM packages were published.
The hackers published the allegedly stolen information, including names, addresses, email addresses, and phone numbers.
Hackers stole the customers’ shipping information, including names, addresses, email addresses, and phone numbers.
The security defect is described as an SQL injection that could allow attackers to achieve remote code execution.
The Rust-based macOS infostealer harvests users’ passwords, keychain information, Chromium-based browser data, and Safari cookies.
The first exploitation attempts targeting CVE-2026-71362 were observed shortly after Adobe released patches.
Attackers with Author-level user or higher permissions could exploit the flaw via malicious Postscript files.
The vulnerabilities could allow attackers to log in with random usernames and passwords or impersonate any FortiGate appliance.
Tracked as CVE-2026–59310, the directory traversal bug allows remote attackers to execute arbitrary code.
Dropped on Patch Tuesday, the exploit allows any user to spawn a shell with System privileges.
The cybersecurity startup will use the fresh investment to scale its product, engineering, sales, and marketing teams.
Affecting European contract logistics operations at eight Ceva warehouses, the incident caused shipment delays for multiple customers.
LiteLLM was compromised through the Trivy hack and abused to distribute information-stealing malware to its users.
The bug allowed attackers to gain full control of the victims’ systems and deploy the ForestTiger backdoor.
The vulnerabilities could be exploited to leak credentials for external SQL connections or crash an agent service.
The security defects could allow unauthenticated attackers to execute arbitrary code remotely and read sensitive data.
A use-after-free in the afd.sys Windows kernel-mode driver has been exploited to gain SYSTEM privileges.
The security defects could be exploited for arbitrary code execution and denial-of-service.
Impacting Zoom annotation, the bug could be exploited by a meeting participant to execute code on another participant’s machine.
SAP released 28 new and two updated security notes, including four notes dealing with critical-severity bugs.