Attackers dumped everything they harvested from LiteLLM builds during a 40-minute window in March. Here is what is inside and what it says about where secrets live.
BSidesLV 2026 presenters showed how attackers are increasingly exploiting valid trust relationships instead of breaking through the front door, and what we need to do about it.
Attackers are using compromised hotel Wi-Fi routers to redirect users to Microsoft 365 phishing sites, according to researchers at ReliaQuest. The attacks were observed in multiple U.S. cities, as well as across India and Saudi Arabia. These types of DNS poisoning attacks can send users to phishing sites with very little evidence that something suspicious has taken place.
Threat actors are increasingly abusing trusted workflows to carry out attacks, according to a new report from Gen Digital. “ are not only sending malicious links or dropping malware,” the report says. “They are abusing context, sessions, workflows, brands, update systems, advertising platforms and delegated authority.
You cannot protect what you do not know exists. That statement has been true throughout the history of cybersecurity, but it has become even more important as organizations adopt new technologies and employees gain access to powerful AI tools. While many organizations focus on defending against external threats, they often overlook a growing problem much closer to home: devices, applications, and services operating within their environment that nobody knows about.
Most companies designed their resource permissions with a human user in mind. A senior engineer may be able to deploy to production, query a sensitive database, or revoke another user's access. Those privileges come with risk, but that risk has traditionally been bounded by two assumptions: the engineer will use human judgment, and the engineer can only act at human speed.
AI has enabled employees across every team to build applications faster than ever before. But that speed is also what's keeping every CISO up at night: any employee can build an application, deploy it to the public Internet, and accidentally expose internal work or company data. Today, we're launching new tools to make it easy to keep your applications hosted on Workers private.
Every enterprise security leader is being asked the same question by their board: are we secure against AI risk? Most cannot answer it with confidence, and the reason is rarely a lack of tools. It is a lack of visibility. AI has spread through enterprises faster than almost any technology before it. Developers wire large language model APIs into internal tools. Business teams stand up copilots and chat assistants. Data science teams build retrieval pipelines against customer and financial data.
As technology grows at a rapid pace, many organizations have switched to new ways of working. Now, hybrid work environments are extremely common, with many organizations hiring employees who work remotely. And then there is the rapid growth of artificial intelligence (AI), which has further changed the way operations are carried out in organizations. Technology has significantly improved the efficiency and accuracy of work, but it has also increased the attack surface.
You're in the middle of a normal week, and a partner calls because a client can't open a shared matter folder. Then the help desk finds encrypted files, a strange login from overnight, and an inbox rule that forwarded privileged emails outside the firm. That's the starting point for cyber security for lawyers, not a policy memo, and it's why your firm needs controls that protect confidentiality, preserve evidence, and prove due care when the pressure is on.