π΅οΈ RESEARCH & DEEP DIVES
-
TeamPCP Trivy Compromise Led to Malicious LiteLLM Releases
TeamPCP used compromised Trivy access to publish malicious LiteLLM releases.- LiteLLM users and CI/CD pipelines worldwide were exposed, with more than 2,500 organizations potentially affected.
- LiteLLM versions 1.82.7 and 1.82.8 were maliciously published to PyPI on March 24 and remained available for about 40 minutes.
- Compromised Trivy tooling exposed LiteLLMβs PyPI publishing token, which attackers used to upload the releases outside the official CI/CD workflow.
- A litellm_init.pth startup hook harvested environment variables, SSH and cloud credentials, Kubernetes tokens, database passwords, and AI API keys.
- Stolen data was encrypted and sent to models.litellm[.]cloud.
π Source: github.com Β· π Coverage: reddit.com Β· π via r/cybersecurity
-
Iranian Intelligence Targets Israeli Journalists With WhatsApp and Telegram Phishing
Iranian intelligence is targeting Israeli journalists with phishing attacks.- Israeli journalists, including Haaretz reporters, are being targeted.
- Attackers seek political and security information, journalistic sources, and working materials.
- Operatives impersonate known entities or fellow reporters on WhatsApp and Telegram.
- Personalized messages offer interviews, cooperation, or exclusive material before directing targets to malicious links or fake login pages.
- The links can steal credentials, compromise Google accounts, and take over mobile phones.
π Coverage: haaretz.com Β· π via @metacurity@infosec.exchange
-
AppFlowy Cloud Exposes Authenticated SQL Injection in qcuiknote
AppFlowy Cloud has a high-severity authenticated SQL injection in qcuiknote.- Self-hosted AppFlowy Cloud deployments are affected.
- The qcuiknote feature is vulnerable to SQL injection, tracked as CVE-2026-16007.
- Authenticated users with qcuiknote access can inject arbitrary SQL queries.
- Successful exploitation can exfiltrate data from the underlying SQL database.
- The vulnerability has a CVSS 4.0 score of 7.1.
π Coverage: projectblack.io Β· π via r/netsec
π ADVISORIES
-
π Source for Franceβs DGFiP confirms taxpayer data theft affecting 678,000 users β presse.economie.gouv.fr
-
π Source for HoneyMyte Adds Signed Windows Kernel Rootkit to CoolClient Backdoor β securelist.com
π CVEs & KEV
-
CVE-2026-74845 β CVSS 8.7 β 2100 Technology|Official Document Management System - Arbitrary File UploadOf...
-
CVE-2026-74578 β CVSS 7.1 β crypto: algif_skcipher - force synchronous processing on trees without ctx->s...