Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations

Two malicious LiteLLM releases sat on PyPI for about 40 minutes in March carrying credential-stealing code capable of harvesting cloud keys, SSH keys, Kubernetes tokens, database passwords, and other secrets from systems that installed them.

Threat intelligence firm CloudSEK now says a dataset it obtained, built from roughly 434,000 files the attackers captured, maps potential exposure to more

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

AI Coding Agents Found Triggering Endpoint Security Rules Built to Catch Attackers

AI Coding Agents Found Triggering Endpoint Security Rules Built to Catch Attackers Sophos looked at a week of its own endpoint data and found that AI coding agents such as

Attack Update: Top 5 Attack-IPs auf doode.info – 24.09.2026

Watchtower Attack Update. Hier die aktuellen Top 5 Attack-IPs, die auf doode.info klopfen. 89.167.35.212 — 493 requests (recent log) 216.73.217.60 — 260 requests (recent log) 45.148.10.21 — 174 requests (recent

I Have Thoughts on the iPhone Air

I Have Thoughts on the iPhone Air Source: Hacker News