Fresh LiteLLM Vulnerability Exploited Shortly After Disclosure
2026-04-30T07:24:08Z•bc79a6f55374ead7ecff3122886b0159ed33114d489562c691ad3706ac22ccdd
agentic aibrowserscheckmarxchrome 147cve-2026-3854cyber insurancedata exfiltrationexploitationfirefox 150githubhandalaics/otlitellmopenemrpatient dataproxy vulnerabilityrcerdpsecurity updatesshinyhunterssupply chainvimeovncwhatsapp
What happened
A SecurityWeek roundup covering multiple high-impact incidents and disclosures: a newly disclosed LiteLLM proxy vulnerability was quickly exploited to read and potentially modify proxy databases; tens of thousands of Internet-facing RDP/VNC servers (including hundreds exposing ICS/OT) were identified; Checkmarx confirmed data exfiltration from its GitHub environment following a supply-chain compromise; Iranian-aligned group Handala targeted US troops via WhatsApp messages; Aisle reported 38 OpenEMR flaws that could expose/alter patient records; Chrome 147 and Firefox 150 rollouts fix critical/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityweek
- Record identifier
- bc79a6f55374ead7ecff3122886b0159ed33114d489562c691ad3706ac22ccdd
- Enrichment time
- 2026-04-30T07:24:08Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.