Recent Navia data breach impacts HackerOne employee data

2026-03-25T14:51:46Zb8c8a5f65ce54c07ffe2ec530fc7f9cb9701ad290b7086d45a343b54dde9f353
AstraZenecaCVE-2025-62843CVE-2025-62844CVE-2025-62845CVE-2025-62846CVE-2026-3055Citrix-NetScalerFCCHackerOnePwn2OwnQNAPQualDermStoatWaffleTeamPCPTrivyVSCodecredential-theftdata-breachkubernetesliteLLMremote-executionrouterssoftware-supply-chainsupply-chain

What happened

This feed aggregates multiple high-impact security events: several data breaches (Navia compromise exposing ~300 HackerOne employees, QualDerm Partners breach affecting ~3.1M people, claimed Lapsus$ exfiltration from AstraZeneca, and a Dutch Ministry of Finance incident). A notable software-supply-chain compromise backdoored LiteLLM (malicious v1.82.7–1.82.8 releases, likely via Trivy CI/CD) to steal credentials, move laterally in Kubernetes, and maintain persistence. Multiple vulnerabilities were disclosed/fixed: Citrix NetScaler critical memory overread (CVE-2026-3055, CVSS 9.3) that can una

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
b8c8a5f65ce54c07ffe2ec530fc7f9cb9701ad290b7086d45a343b54dde9f353
Enrichment time
2026-03-25T14:51:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.