How LiteLLM turned developer machines into attackers’ credential vaults

The most active enterprise infrastructure within a company is the developer workstation. That laptop is where credentials are created, tested, cached, copied, and reused across services, bots, build tools, and now local AI agents. In March 2026, TeamPCP threat actors proved how valuable developer machines can be. A supply chain attack against LiteLLM, a popular […]

Qilin and Warlock ransomware uses vulnerable drivers to disable over 300 EDR tools

Ravi LakshmananApril 6, 2026Ransomware/Endpoint Security According to Cisco Talos and Trend Micro research, threat actors associated with Qilin and Warlock ransomware operations have been observed using Bring Your Own Vulnerability Driver (BYOVD) techniques to silence security tools running on compromised hosts. The Qilin attack analyzed by Talos deployed a malicious DLL named ‘msimg32.dll’ that started […]

BKA identifies REvil leader behind 130 ransomware attacks in Germany

Ravi LakshmananApril 6, 2026Cybercrime/Financial Crime The German Federal Criminal Police (also known as BKA or Bundeskcriminalamt) has revealed the identity of the main threat actor associated with the now-defunct REvil (also known as Sodinokibi) ransomware-as-a-service (RaaS) operation. The actor, who goes by the alias UNKN, acts as a representative for the group and promoted ransomware […]

$285M Drift Hack Tracks 6-Month North Korean Social Engineering Operation

Drift revealed that the April 1, 2026 attack, which resulted in the theft of $285 million, was the culmination of a months-long, targeted, well-planned social engineering operation by the Democratic People’s Republic of Korea (DPRK) that began in the fall of 2025. The Solana-based decentralized exchange described the attack as a “six-month effort” and attributed […]

36 malicious npm packages exploit Redis, PostgreSQL to deploy Persistent Implant

Ravi LakshmananApril 5, 2026Malware / DevSecOps Cybersecurity researchers discovered 36 malicious packages in the npm registry disguised as Strapi CMS plugins but with different payloads to facilitate exploitation of Redis and PostgreSQL, deploy reverse shells, harvest credentials, and drop persistent implants. “Every package contains three files (package.json, index.js, postinstall.js), has no description, repository, or homepage, […]

Fortinet patch actively exploits CVE-2026-35616 in FortiClient EMS

Ravi LakshmananApril 5, 2026Vulnerabilities/API Security Fortinet has released an out-of-band patch for a critical security flaw affecting FortiClient EMS and announced that the flaw is being exploited in the wild. This vulnerability is tracked as CVE-2026-35616 (CVSS score: 9.1) and is described as a pre-authentication API access bypass leading to privilege escalation. “Improper Access Control […]

China-linked TA416 targets European governments with PlugX and OAuth-based phishing

China-aligned threat actors have been targeting European governments and diplomatic institutions since mid-2025, after two years of minimal targeting in the region. This campaign is attributed to TA416, a cluster of activity that overlaps with DarkPeony, RedDelta, Red Lich, SmugX, UNC6384, and Vertigo Panda. “This TA416 activity included multiple waves of web bug and malware […]

UNC1069 Axios Maintainer social engineering led to npm supply chain attack

Ravi LakshmananApril 3, 2026Threat Intelligence/Malware The administrator of the Axios npm package acknowledged that the supply chain compromise was the result of a highly targeted social engineering campaign orchestrated by North Korean threat actors, tracked as UNC1069. Administrator Jason Seman said the attackers first approached him posing as the founders of legitimate, well-known companies and […]

Why third-party risk is the biggest gap in clients’ security posture

The next major breach to hit your clients likely won’t come from behind your walls. It can be delivered through a vendor they trust, a SaaS tool contracted by their finance team, or a subcontractor that no one in IT knows about. This is a new attack surface, and most organizations are ill-prepared for it. […]