MEDIUMSupply Chain
Global

Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations

·Source: The Hacker News

Updated:

Executive Summary

Two malicious LiteLLM releases sat on PyPI for about 40 minutes in March carrying credential-stealing code capable of harvesting cloud keys, SSH keys, Kubernetes tokens, database passwords, and other secrets from systems that installed them. Threat intelligence firm CloudSEK now says a dataset it obtained, built from roughly 434,000 files the attackers captured, maps potential exposure to more

Analysis

Two malicious LiteLLM releases sat on PyPI for about 40 minutes in March carrying credential-stealing code capable of harvesting cloud keys, SSH keys, Kubernetes tokens, database passwords, and other secrets from systems that installed them. Threat intelligence firm CloudSEK now says a dataset it obtained, built from roughly 434,000 files the attackers captured, maps potential exposure to more
Source Attribution

Originally published by The Hacker News on Aug 12, 2026.

Related Threats

CRITICALSupply Chain

Critical GitLab flaw allows attackers to delete and modify public repos

GitLab has fixed a critical vulnerability that could allow unauthenticated attackers to perform unauthorized modifications inside code repositories or to completely delete them with a single HTTP request. The patched releases also address a second high-risk cross-site request forgery (CSRF) flaw. The critical vulnerability, tracked as CVE-2026-19478 , is described as a code injection issue through

CVE-2026-19478CVE-2026-19650
CSO Online
MEDIUMSupply Chain

Securing Software at the Speed of AI: What Four Years of Data Reveal

<div class="hs-featured-image-wrapper"> <a href="https://www.sonatype.com/blog/securing-software-at-the-speed-of-ai-what-four-years-of-data-reveal" title="" class="hs-featured-image-link"> <img src="https://www.sonatype.com/hubfs/AI%20ERA%20SOFTWARE%20ASSEMBLY%20BLOG.png" alt="Image with statistics and text regarding AI software assembly" class="hs-featured-image" style="width:auto !important; max

Sonatype (Maven/npm)
HIGHSupply Chain

OpenAI president’s blog pushing agentic AI most notable for what it did not say

OpenAI president Greg Brockman on Sunday warned enterprise CISOs that they need to more aggressively embrace agents if they want to survive upcoming cyberattacks. Brockman said in a blog post that it has become “increasingly clear” that company systems are hiding “significant flaws, and defenders need to find and fix them before attackers do.” He added: “The Hugging Face incident showed that we un

CSO Online