Unsecured Perforce Servers Expose Sensitive Data From Major Orgs

2026-04-21T13:24:13Zf9060e3ef0320f63ae1f3e2d8613d42ff7fa65e325a1eb092b2de8970bd18f29
CISACiscoKEVKelp-DAOKenticoLantronixLayerZeroLoadMasterMOVEitNorth-KoreaOS-command-injectionP4PerforceProgressRPC-poisoningSilexWAFZimbracrypto-heistdata-breachdata-exposurehealthcare-breachmisconfigurationremote-code-executionserial-to-IP-converter','OT-security','QEMU','defense-evasion','

What happened

This SecurityWeek feed covers multiple high-impact security stories: a researcher found over 1,500 unsecured Perforce P4 instances exposing sensitive files; Progress released patches for multiple MOVEit WAF and LoadMaster flaws (including issues leading to remote code execution, OS command injection and WAF bypass); CISA expanded its KEV catalog with eight flaws (five previously observed exploited) affecting vendors including Cisco, Kentico and Zimbra. Other notable items: data breaches at several U.S. healthcare organizations affecting ~600,000 people; a $290M Kelp DAO crypto heist attributed

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityweek
Record identifier
f9060e3ef0320f63ae1f3e2d8613d42ff7fa65e325a1eb092b2de8970bd18f29
Enrichment time
2026-04-21T13:24:13Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Unsecured Perforce Servers Expose Sensitive Data From Major Orgs · Baitaphish