Broken VECT 2.0 ransomware acts as a data wiper for large files

2026-04-29T07:23:33Zf01e1cfefd950797e857f7edf8a7d6212a59cea77cb28936605a88d4193bcd45
anodotcheckmarxcve-2026-42208data-breachdata-wiperexchange-onlineglassworminfostealerlapsuslaw-enforcementlitellmmicrosoftopenvsxphishingpypiransomwarerobinhoodscattered-spidersilk-typhoonsms-blastersql-injectionsupply-chaintls-deprecationvectvimeo

What happened

This BleepingComputer roundup covers multiple active threats and incidents: a bug in VECT 2.0 ransomware causes large files to be permanently wiped instead of encrypted; attackers are actively exploiting a critical pre-auth SQL injection in the LiteLLM LLM gateway (CVE-2026-42208) to harvest sensitive data; Vimeo data was exposed following the Anodot breach; Checkmarx confirmed LAPSUS$ leaked GitHub data; GlassWorm resumed attacks via 73 “sleeper” OpenVSX extensions; a popular PyPI package (elementary-data) was poisoned to deliver an infostealer; Robinhood account-creation logic was abused to送

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
f01e1cfefd950797e857f7edf8a7d6212a59cea77cb28936605a88d4193bcd45
Enrichment time
2026-04-29T07:23:33Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.