Researchers uncover WebRTC skimmer bypassing traditional defenses
2026-03-26T14:51:55Z•e9a66a6d76c831a9b097962ed66ba5e63485bbb7a03d7cf1802b2a679228c8bd
AstraZenecaCVE-2025-15517HackerOneIoTLapsus$LeakBaseLiteLLMNaviaQualDermTP-LinkTeamPCPTrivy-CIWebRTCbotnetconviction','FCC-policydata-breachdata-exfiltrationfirmware-takeoverlaw-enforcementmalicious-releasepayment-skimmerrouterssupply-chainvulnerabilityweb-application-security
What happened
Multiple high-impact cybersecurity events: researchers disclosed a new WebRTC-based payment skimmer that uses WebRTC data channels to load and exfiltrate payment data, evading traditional detection; a supply-chain compromise of LiteLLM (malicious v1.82.7–1.82.8, attributed to TeamPCP) introduced credential-stealing and Kubernetes lateral-movement tools; TP-Link Archer NX routers patched for an authentication-bypass/firmware takeover (CVE-2025-15517); several significant data breaches affecting organizations and third-party providers (Navia affecting HackerOne employees, QualDerm Partners ~3.1M
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- e9a66a6d76c831a9b097962ed66ba5e63485bbb7a03d7cf1802b2a679228c8bd
- Enrichment time
- 2026-03-26T14:51:55Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.