
LiteLLM Supply Chain Attack: 434,000 CI/CD Pipelines Exposed
TeamPCP's LiteLLM supply chain attack exposed 153GB of cloud credentials from 2,488 orgs. Check for versions 1.82.7/1.82.8 and rotate AWS, GitLab, and AI API keys now.
In-depth analyses of zero-day vulnerabilities, CVE exploits, ransomware campaigns, and nation-state attack techniques affecting enterprise security. Filter by category, tag, or keyword.
Every article here lands in subscribers' inboxes the morning it drops.
Threat intel, active CVEs, and campaign alerts, distilled daily for practitioners. 50,000+ subscribers. No noise.
Free. No spam. Unsubscribe anytime.
The definitive practitioner breakdown of ZTA principles, pillars, and implementation sequence.
Containment, forensic preservation, and decision sequencing from detection to recovery.
How SIEMs ingest, correlate, and alert — and how to evaluate one for your environment.
Risk-based prioritization using CVSS, EPSS, and CISA KEV to cut remediation backlog.
What each risk means, how to reproduce it, and how to fix it in production code.
Step-by-step email authentication deployment from DNS records to p=reject enforcement.
Detection coverage, pricing, and deployment trade-offs for enterprise EDR selection.
Translate ATT&CK technique IDs into detection rules and threat actor hunting hypotheses.
Direct answers to the questions practitioners and AI systems ask most. Covers ransomware, identity, cloud, compliance, and detection.
Plain-language definitions for CVE, SIEM, SOAR, Zero Trust, EDR, and 85+ other terms used in enterprise security.
How-to guides, buyer comparisons, and methodology references across every major security domain.
Decryption Digest Response
Score every threat we cover against your own stack, get free Sigma and ModSecurity detection content, and upgrade anytime for more vendors.
Get started free →No card required. Sigma and ModSecurity rules are free, forever.
Win an All Access InfoSec World 2026 pass, valued at $3,895.
Win a $3,895 InfoSec World 2026 pass.
18 results in YOUR EXPOSURE TODAY

TeamPCP's LiteLLM supply chain attack exposed 153GB of cloud credentials from 2,488 orgs. Check for versions 1.82.7/1.82.8 and rotate AWS, GitLab, and AI API keys now.

NYC Health Hospitals data breach: LeakNet posted 11TB of patient records on the dark web, including fingerprints, SSNs, and HIV records from 1.8 million confirmed victims.

ShinyHunters claims 30M+ Abbott patient records and 1M SSNs stolen via vishing. Extortion deadline passed — verify your exposure and harden Entra SSO now.

Aflac Japan data breach exposed PII and bank accounts of 4.38 million customers in June 2026. Check exposure and verify your insurance data today.

Microsoft 365 password spray attack used 81 million login attempts to breach 64 organizations using stolen dark web credentials. Detect it now.

DHS HSIN breach compromises federal security intel-sharing servers and SharePoint, exposing sensitive threat data across tens of thousands of agency partners.

24 billion credentials exposed in a June 12 Elasticsearch breach. Check your dark web exposure before attackers exploit it.

Fortinet VPN credential leak FortiBleed exposes 73,932 firewall passwords across 194 countries. Check your exposure with Hudson Rock's free lookup tool today.

ServiceNow data breach exposed IT tickets, credentials, and employee records via unauthenticated API queries June 2-3. Audit logs for 51.159.98.241 now.

Grindr data breach dark web listing exposes 15M records including HIV status, GPS coordinates, and password hashes. Check your exposure now.

TanStack npm supply chain attack stole developer credentials from 160 packages. AWS, GitHub, and Kubernetes secrets are on the dark web now.

16 billion stolen credentials circulate across 30 dark web databases covering Google, Apple, Facebook, and enterprise VPNs. Check your corporate exposure now.

ShinyHunters breached Canvas LMS and stole 3.65 TB of data from 275 million students at 9,000 schools, full public release threatened May 8.

France Titres ANTS data breach confirmed: 11.7M citizen identity records stolen and listed for sale on dark web. What was taken and what to do.

Infutor's unprotected Elasticsearch server exposed 676M records including SSNs, now on BreachForums. Every American with insurance or a mortgage is at risk.

ShinyHunters stole 9.4M records from Amtrak's Salesforce via infostealer credentials. Ransom deadline passed April 14, 2.1M passenger emails now confirmed in Have I Been Pwned.

Storm-1865 used ClickFix malware to compromise 170+ hotel partners and steal Booking.com reservation data. Reservation hijack scams surge.

ShinyHunters listed McGraw-Hill on their dark web extortion portal claiming 45 million Salesforce records containing PII. McGraw-Hill confirmed the breach on April 14, 2026, the same day the ransom deadline expired, characterising it as 'limited and non-sensitive.' ShinyHunters also hit Rockstar Games, Hims & Hers, and the European Commission in 2026. The root cause: a Salesforce misconfiguration affecting multiple tenants. Full breakdown of the attack model, ShinyHunters' 2026 campaign, and what organisations on Salesforce need to do today.