Researchers at Endor Labs, have discovered a supply chain attack on the popular Python package LiteLLM on PyPI, with malicious code injected into versions 1.82.7 and 1.82.8, which have been withdrawn. The package is used in AI environments and developer tools, with an estimated 95 million downloads per month. The malicious packages included credential-stealing malware, including a .pth file that can run automatically when Python is started, enabling bad actors to harvest SSH keys, cloud credentials, API keys, and environment variables from infected systems. In some cases, the malware was also designed to access Kubernetes secrets and implant persistent backdoors on the compromised systems. The incident…
Kirsten Doyle
No longer are geopolitical standoffs settled on the traditional battlefields of diplomacy and arms; now, the digital realm has emerged as the arena for these conflicts. In this article, we bring together industry experts to discuss the dynamics of the development of cyber threats during unstable international circumstances, the role of automation and AI in the realm of cyber war, and the key issues that organisations, regardless of their level of proximity to the current geopolitical hotspot, need to be focusing on to ensure their survival in this increasingly hostile digital arena. Know thy enemy and know yourself Carl von Clausewitz famously…
The US Federal Communications Commission (FCC) has announced a plan to prevent the authorization and import of new consumer routers produced outside the US, adding them to its “Covered List” of items that pose a national security risk. This decision is a result of a government assessment that found routers produced abroad pose a critical cybersecurity and supply chain risk to US infrastructure, which has, in the past, been used in cyber incidents and could be used for network disruption, espionage, or data theft, similar to previous decisions regarding drones produced abroad. Consumer routers produced abroad dominate the US market, with an…
A newly disclosed flaw in Ubuntu’s Snap ecosystem is raising fresh concerns about local privilege escalation risks in default Linux environments. Researchers at Qualys have identified CVE-2026-3888, a high-severity vulnerability that allows a low-privileged local user to escalate access to full root control on affected systems. The problem affects default installs of Ubuntu Desktop versions 24.04 and later. In essence, the problem is caused by an unexpected interaction between two trusted components of the system: snap-confine, which is a component of application sandboxing, and systemd-tmpfiles, which is a component of temporary file cleaning. Although these components are intended to improve the security and hygiene of the system, the…
Companies House, the UK’s official registrar of companies, has disclosed a security flaw in its WebFiling service that exposed sensitive data tied to more than five million registered businesses. The issue traces back to a system update rolled out in October 2025 and went unnoticed for five months before it was flagged. The vulnerability meant logged-in users could access other companies’ records simply by manipulating browser navigation. That potentially put home addresses, email addresses, and dates of birth of company officers in view, and in some cases, may even have opened the door to unauthorized changes to filings. In response, the organisation pulled the affected service offline to…
Since the outbreak of the Middle East conflict on 28 February 2026, Akamai has seen a surge of 245% in cyberattacks against key businesses and institutions in North America, Europe, and some Asian Pacific countries. One group in particular, Handala (widely believed to have ties to Iranian intelligence) has claimed responsibility for a destructive data-wiping attack on Stryker, the global medical technology firm based in Michigan. At the same time, geopolitically motivated hacktivists are increasingly routing activity through proxy infrastructure in countries such as Russia and China, generating billions of connection attempts specifically engineered for abuse. The bulk of this malicious traffic is hitting a…
The Qualys Threat Research Unit (TRU) has identified nine vulnerabilities in AppArmor, a Linux Security Module. The vulnerability has been present since 2017 (version v4.11). AppArmor is the default mandatory access control system for Ubuntu, Debian, SUSE, and several cloud platforms. Its presence in all these systems and its use in all these platforms make the threat landscape much wider. This vulnerability, disclosed in the “CrackArmor” advisory, is a confused deputy vulnerability. It allows unprivileged users to manipulate security profiles via pseudo-files and to execute arbitrary kernel code. These weaknesses, in turn, lead to local privilege escalation to the root account through intricate interactions with tools like…
TELUS Digital has fallen victim to a security incident in which unsanctioned actors accessed its systems. Upon learning of this incident, the company said it took immediate action to resolve it and prevent any future breaches of its systems and environment. “All business operations within TELUS Digital remain fully operational, and there is no evidence of disruption to customer connectivity or services. As part of our response, we have engaged leading cyber forensics experts to support our investigation, and we are working with law enforcement.” The notorious cybercrime group ShinyHunters has taken responsibility for the attack and has also claimed that the group…
Starbucks has disclosed a data breach attackers gained access to hundreds of employees’ Starbucks Partner Central accounts, which are used for managing employment information, personal data, benefits, and HR information. In a letter sent to affected staff members, the company said: “On or about February 6, 2026, Starbucks Corporation (“Starbucks” or “we”) became aware of potential unauthorized access to certain Starbucks Partner Central accounts.” Starbucks is the world’s largest coffee shop chain with 380,000 employees and nearly 41,000 shops in 88 countries. In a data breach notification filed with the Attorney General in Maine, Starbucks said 889 employees were affected. “Upon becoming aware, Starbucks commenced an investigation and began taking measures…
Security researchers have demonstrated how a growing class of AI safety controls (known as AI judges) can be manipulated into approving content they are supposed to block. In new research published by cybersecurity firm Palo Alto Networks’ threat intelligence team Unit 42, analysts describe how automated “fuzzing” techniques can uncover hidden weaknesses in the large language models that many organizations now rely on as automated gatekeepers. These models are increasingly used to evaluate whether AI-generated responses are safe, policy-compliant, or suitable for users. But the research suggests that these digital referees can themselves be fooled, sometimes by nothing more than harmless-looking formatting characters. Testing the AI Gatekeepers …
