Related Threat Clusters
-
Critical Unauthenticated RCE Vulnerability in LiteLLM Exploited in the Wild
A critical command injection vulnerability, CVE-2026-42271, in LiteLLM, an open-source AI gateway, allows unauthenticated remote code execution (RCE) when chained with CVE-2026-48710, a Host header validation bypass in…
17 articles · Updated June 9, 2026 -
SonicWall SMA1000 Faces Critical Zero-Day Exploitation
SonicWall disclosed two critical vulnerabilities in its SMA1000 series appliances, CVE-2026-83548 and CVE-2026-83549, which are being actively exploited. CVE-2026-83548 is a pre-authentication server-side request…
40 articles · Updated September 2, 2026 -
CISA Issues Urgent Directive to Patch Check Point VPN Vulnerability Exploited by Ransomware
CISA has mandated federal agencies to patch a critical vulnerability in Check Point VPN products within 72 hours due to active exploitation by the Qilin ransomware group. The vulnerability, tracked as CVE-2026-42271,…
8 articles · Updated June 9, 2026 -
Multiple Critical Vulnerabilities Exploited in SonicWall and SharePoint Systems
In July 2026, several critical vulnerabilities were exploited, impacting SonicWall SMA1000 appliances and SharePoint servers. Two zero-day vulnerabilities, CVE-2026-15409 and CVE-2026-15410, were discovered in SonicWall…
2 articles · Updated July 28, 2026 -
LiteLLM Supply Chain Attack Exposes Critical Credentials
On March 24, 2026, two versions of the LiteLLM Python package (1.82.7 and 1.82.8) were compromised on PyPI, embedding credential-stealing payloads. The attack, linked to the TeamPCP threat actor, exploited a…
3 articles · Updated June 12, 2026 -
AI Infrastructure Under Siege: Session Hijacking and Exploits Surge
Recent cybersecurity incidents have targeted AI platforms and enterprise systems, with significant exploits reported. Notable vulnerabilities include the PaperCut remote code execution flaw (CVE-2026-65105) being…
5 articles · Updated September 5, 2026 -
Critical SQL Injection Vulnerability in LiteLLM Actively Exploited
Hackers are exploiting a critical SQL injection vulnerability in the LiteLLM open-source large-language model gateway, tracked as CVE-2026-42208. This pre-authentication flaw allows attackers to access sensitive…
11 articles · Updated April 28, 2026 -
Critical Privilege Escalation Vulnerabilities in LiteLLM Disclosed
Two critical vulnerabilities (CVE-2026-47101 and CVE-2026-47102) have been identified in LiteLLM versions prior to 1.83.14. CVE-2026-47101 allows authenticated internal users to create API keys with unauthorized access,…
2 articles · Updated May 22, 2026 -
Miggo Security Introduces Rapid Mitigation for Recent Vulnerabilities
Miggo Security announced its Defense-in-Depth Mitigation solution at Black Hat USA on July 28, 2026. This new approach allows organizations to implement coordinated mitigation strategies at both the edge and application…
2 articles · Updated July 28, 2026 -
LiteLLM Python Package Compromised in Major Supply Chain Attack by TeamPCP
On March 24, 2026, two malicious versions of the LiteLLM Python package (1.82.7 and 1.82.8) were published on PyPI, containing credential-stealing malware. The attack, attributed to the TeamPCP threat group, exploited…
53 articles · Updated March 24, 2026
Recent Intelligence Reports
- AI Attack Surfaces and Supply Chain Threats Define the Week — Esecurityplanet · September 5, 2026
- CISA Adds 7 Exploited Flaws as Attackers Target AI Infrastructure — Esecurityplanet · September 4, 2026
- CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners — Thehackernews · September 3, 2026
- Hackers Target AI Infrastructure With RCE and API Key Theft — Cypro · August 28, 2026
- Tracker — www.globenewswire.com · August 27, 2026
- KELA research leads to alleged TeamPCP Members Arrested — Markets.Businessinsider · August 27, 2026
- Australian police arrest two over TeamPCP hacks targeting Mercor, OpenAI, and others — Techcrunch · August 27, 2026
- LiteLLM Attack Shows AI Infrastructure Is Becoming a Strategic Software Supply Chain Target — Gbhackers · August 11, 2026