All posts
Topic
Litellm
3 articles on litellm.
CISA Flags LiteLLM CVE-2026-59822: Attackers Forge Authenticated MCP Sessions With No Credentials
CISA added LiteLLM CVE-2026-59822 (CVSS 8.8) to its Known Exploited Vulnerabilities catalog on Sep 3, 2026 โ an unauthenticated attacker can establish an authenticated MCP session against the popular AI gateway. Why the gateway is the prize, and how to respond.
September 3, 2026
Attackers Are Hunting Your AI Gateway: Inside the LiteLLM / RAGFlow / Kestra Campaign
Microsoft detailed a coordinated campaign (Aug 2026) hitting exposed AI infrastructure โ LiteLLM, RAGFlow, Kestra โ to steal every model-provider API key and then mine crypto on the box. The CVEs, the credential-harvesting playbook, and how to lock your AI control points down.
August 26, 2026
The LiteLLM Supply Chain Attack: What TeamPCP Stole, Who It Hit, and What to Do Now
Backdoored LiteLLM 1.82.7 and 1.82.8 stayed on PyPI for 40 minutes in March 2026 โ long enough to compromise over 2,400 organizations. A 153GB archive of the stolen data has now surfaced. Here is exactly what happened, the IOCs, and the remediation checklist.
August 13, 2026