Fresh LiteLLM Vulnerability Exploited Shortly After Disclosure

2026-04-30T07:24:08Zbc79a6f55374ead7ecff3122886b0159ed33114d489562c691ad3706ac22ccdd
agentic aibrowserscheckmarxchrome 147cve-2026-3854cyber insurancedata exfiltrationexploitationfirefox 150githubhandalaics/otlitellmopenemrpatient dataproxy vulnerabilityrcerdpsecurity updatesshinyhunterssupply chainvimeovncwhatsapp

What happened

A SecurityWeek roundup covering multiple high-impact incidents and disclosures: a newly disclosed LiteLLM proxy vulnerability was quickly exploited to read and potentially modify proxy databases; tens of thousands of Internet-facing RDP/VNC servers (including hundreds exposing ICS/OT) were identified; Checkmarx confirmed data exfiltration from its GitHub environment following a supply-chain compromise; Iranian-aligned group Handala targeted US troops via WhatsApp messages; Aisle reported 38 OpenEMR flaws that could expose/alter patient records; Chrome 147 and Firefox 150 rollouts fix critical/

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityweek
Record identifier
bc79a6f55374ead7ecff3122886b0159ed33114d489562c691ad3706ac22ccdd
Enrichment time
2026-04-30T07:24:08Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Fresh LiteLLM Vulnerability Exploited Shortly After Disclosure · Baitaphish