Researchers uncover WebRTC skimmer bypassing traditional defenses

2026-03-26T14:51:55Ze9a66a6d76c831a9b097962ed66ba5e63485bbb7a03d7cf1802b2a679228c8bd
AstraZenecaCVE-2025-15517HackerOneIoTLapsus$LeakBaseLiteLLMNaviaQualDermTP-LinkTeamPCPTrivy-CIWebRTCbotnetconviction','FCC-policydata-breachdata-exfiltrationfirmware-takeoverlaw-enforcementmalicious-releasepayment-skimmerrouterssupply-chainvulnerabilityweb-application-security

What happened

Multiple high-impact cybersecurity events: researchers disclosed a new WebRTC-based payment skimmer that uses WebRTC data channels to load and exfiltrate payment data, evading traditional detection; a supply-chain compromise of LiteLLM (malicious v1.82.7–1.82.8, attributed to TeamPCP) introduced credential-stealing and Kubernetes lateral-movement tools; TP-Link Archer NX routers patched for an authentication-bypass/firmware takeover (CVE-2025-15517); several significant data breaches affecting organizations and third-party providers (Navia affecting HackerOne employees, QualDerm Partners ~3.1M

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
e9a66a6d76c831a9b097962ed66ba5e63485bbb7a03d7cf1802b2a679228c8bd
Enrichment time
2026-03-26T14:51:55Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.