Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations

Two malicious LiteLLM releases sat on PyPI for about 40 minutes in March carrying credential-stealing code capable of harvesting cloud keys, SSH keys, Kubernetes tokens, database passwords, and other secrets from systems that installed them.

Threat intelligence firm CloudSEK now says a dataset it obtained, built from roughly 434,000 files the attackers captured, maps potential exposure to more

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Eight Myths on Software Engineering and GenAI

Eight Myths on Software Engineering and GenAI Source: Hacker News

Fairphone 6 wide camera experimental Linux support

Fairphone 6 wide camera experimental Linux support Source: Hacker News

China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw

China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw Microsoft has disclosed that Storm-1175, a financially motivated threat actor linked to China, has deployed a previously undocumented ransomware strain