Broken VECT 2.0 ransomware acts as a data wiper for large files
2026-04-29T01:23:46Z•9cfe5a4aa1f07fcb2722a28e65a5bbc753412c0f477a399785d3f22785fce1a4
AnodotCVE-2026-42208CheckmarxExchange Online TLS deprecationGitHub leakGlassWormLAPSUS$LiteLLMMicrosoftOpenVSXPyPIRobinhoodSQL injectionVECT 2.0Vimeo breachactive exploitdata exposuredata-wiperinfostealermalicious extensionsnonce bugpackage compromisephishing abuseransomwaresupply-chain compromise
What happened
Multiple security incidents and vulnerabilities were reported: VECT 2.0 ransomware contains a nonce-handling bug that can permanently destroy large files (acting as a wiper); the LiteLLM LLM gateway is being actively exploited via a critical pre-auth SQL injection (CVE-2026-42208) to access sensitive data; Vimeo confirmed customer/user data exposure following the Anodot breach; Checkmarx had stolen GitHub data leaked by LAPSUS$; GlassWorm returned via 73 malicious “sleeper” OpenVSX extensions; a popular PyPI package (elementary-data) was backdoored to deploy an infostealer; Robinhood’s account
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 9cfe5a4aa1f07fcb2722a28e65a5bbc753412c0f477a399785d3f22785fce1a4
- Enrichment time
- 2026-04-29T01:23:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.