Recent Navia data breach impacts HackerOne employee data
2026-03-25T14:51:46Z•b8c8a5f65ce54c07ffe2ec530fc7f9cb9701ad290b7086d45a343b54dde9f353
AstraZenecaCVE-2025-62843CVE-2025-62844CVE-2025-62845CVE-2025-62846CVE-2026-3055Citrix-NetScalerFCCHackerOnePwn2OwnQNAPQualDermStoatWaffleTeamPCPTrivyVSCodecredential-theftdata-breachkubernetesliteLLMremote-executionrouterssoftware-supply-chainsupply-chain
What happened
This feed aggregates multiple high-impact security events: several data breaches (Navia compromise exposing ~300 HackerOne employees, QualDerm Partners breach affecting ~3.1M people, claimed Lapsus$ exfiltration from AstraZeneca, and a Dutch Ministry of Finance incident). A notable software-supply-chain compromise backdoored LiteLLM (malicious v1.82.7–1.82.8 releases, likely via Trivy CI/CD) to steal credentials, move laterally in Kubernetes, and maintain persistence. Multiple vulnerabilities were disclosed/fixed: Citrix NetScaler critical memory overread (CVE-2026-3055, CVSS 9.3) that can una
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- b8c8a5f65ce54c07ffe2ec530fc7f9cb9701ad290b7086d45a343b54dde9f353
- Enrichment time
- 2026-03-25T14:51:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.