LiteLLM was compromised through the Trivy hack and abused to distribute information-stealing malware to its users.
The post Over 2,500 Organizations Impacted by LiteLLM Supply Chain Attack appeared first on SecurityWeek.
LiteLLM was compromised through the Trivy hack and abused to distribute information-stealing malware to its users.
The post Over 2,500 Organizations Impacted by LiteLLM Supply Chain Attack appeared first on SecurityWeek.
The vulnerability in question is CVE-2026-59310 (CVSS score: 9.8), a directory-traversal vulnerability in the VMware vCenter server that a malicious actor with network access can exploit to execute arbitrary code. Patches for the flaw were
The bug allowed attackers to gain full control of the victims’ systems and deploy the ForestTiger backdoor.
The post Fresh Windows Zero-Day Exploited in North Korean Cyberattacks appeared first on SecurityWeek.
The vulnerabilities could be exploited to leak credentials for external SQL connections or crash an agent service.
The post Ivanti EPM Update Patches Remotely Exploitable Flaws appeared first on SecurityWeek.
Threat intelligence firm CloudSEK now says a dataset it obtained, built from roughly 434,000 files the attackers captured, maps potential exposure to more
The vulnerability, assigned the CVE identifier CVE-2026-58231, is rated 10.0 on the CVSS scoring system. It has been described as a case of insufficient authorization checks and input validation.
“SAP Commerce Cloud allows an
The security defects could allow unauthenticated attackers to execute arbitrary code remotely and read sensitive data.
The post SonicWall Patches Critical Vulnerabilities in Discontinued GMS Platform appeared first on SecurityWeek.
The vulnerability, rooted in Microsoft Defender for Windows, demonstrates a patch bypass for CVE-2026-50656 (CVSS score: 7.8), otherwise known as RoguePlanet.
RoguePlanet has been described
The high-severity flaw, tracked as CVE-2026-20349 (CVSS score: 8.6), is a case of insufficient error checking when processing HTTP requests that could allow an unauthenticated, remote attacker to trigger
CVE-2026-20349 can be exploited remotely without authentication against Secure Firewall ASA and FTD devices.
The post Cisco Patches Firewall Zero-Day Exploited for DoS Attacks appeared first on SecurityWeek.
