As cited
Copy frozen at (site build).
vulnerabilities
Trivy, Not LiteLLM Behind the 2,500 Org Compromise
A compromise affecting approximately 2,500 organizations was primarily driven by a Trivy vulnerability rather than malicious LiteLLM packages as initially suspected. The majority of affected companies experienced exposure before the LiteLLM packages containing malicious code were released.
Why it matters: Organizations using Trivy and LiteLLM need to assess their exposure timeline and prioritize patching Trivy to prevent future exploitation of the underlying vulnerability.
- Source published
- First seen by Cybersecurity Tracker