
The LiteLLM Breach Sat Hidden for Five Months
CloudSEK links a March 2026 LiteLLM compromise to 2,500+ firms and 434,000 CI/CD pipelines. The attack beat a safeguard developers still trust, and the FBI says the credentials are still usable.

CloudSEK links a March 2026 LiteLLM compromise to 2,500+ firms and 434,000 CI/CD pipelines. The attack beat a safeguard developers still trust, and the FBI says the credentials are still usable.

CISA, the FBI, NSA and South Korea jointly named Gunra ransomware on August 10. It breaks in through two Fortinet flaws patched over a year ago. The real finding is patch lag, not the malware.

CVE-2026-9198 chains two Langflow API calls into unauthenticated root access. CISA confirmed active exploitation; 756 attempts from 295 IPs logged by August 12. Why shadow AI tooling is the real gap.

A CVSS 9.6 command injection flaw in Progress Kemp LoadMaster was hit with 792 exploitation attempts before CISA added it to its KEV catalog on August 7, 2026. What load-balancer owners need to know.

Microsoft's own researchers detail how the DeadLock ransomware group hosts its leak site and victim chat on Polygon blockchain smart contracts and the Session messenger, removing the single points of failure law enforcement has relied on to disrupt ransomware operations.

Check Point traced North Korea's Lazarus Group exploiting a Windows kernel flaw against European defense firms since June, patched only on August 11.

Over four days in July 2026, up to eight AI agents built on open-source tools breached 85+ Taiwan government accounts and reached the grid. Why this is an EU risk too.

Cloudflare's H1 2026 DDoS Threat Report shows attackers moving from raw botnets to DNS and CLDAP reflection attacks that exploit other organizations' misconfigured servers. What that shift means for EU and UK security budgets, and why the government sector's 20-rank jump in targeting is a live warning.

CISA confirmed active exploitation of a Cisco ASA and FTD flaw that lets an unauthenticated attacker crash the firewall on demand. Federal agencies have until August 14 to patch.

CERT Polska says a Sandworm-linked pivot through a wind farm's private APN sabotaged a Polish heat plant serving 50,000 residents in December 2025.

Eight AI agents built from free open-source tools breached 21 Taiwan government systems and reached its nuclear regulator. Dream Security's report shows why NIS2 risk now assumes commodity-tooling attackers, not just nation-states.

Researchers decoded 315,320 encrypted reasoning blocks from public AI transcripts and recovered 367 personal-data artifacts and 182 credentials - proof a flagship model's private reasoning is only as safe as its cheapest sibling.
Page 2 / 11
One considered note on infrastructure, governance, and measurement, most mornings. No theory.