
Blog
Articles tagged security from Whatever Works.

Nearly 1 in 10 internet-facing LiteLLM gateways accepted the example "sk-1234" admin key straight from the setup guide. That one key can expose every stored model-provider API key and the cloud credentials behind the gateway. Here's what Wiz found, the four CVEs, and what to check on your own gateway today.
Read article →
CVE-2026-19949 is an unauthenticated SQL injection in All-in-One WP Migration and Backup that allows remote code execution. 3.25 million sites are still running a vulnerable version. Here's what it means, and the steps to secure your site today.
Read article →
FIDO's 2026 report: 5 billion passkeys in use, 90% consumer awareness, and 47% of people more likely to abandon a purchase over a forgotten password. What a passkey actually is, what it costs to add, and when it's worth it for your business.
Read article →