All posts
Topic
Supply Chain
9 articles on supply chain.
When Your LLM Router Turns On You: Tool-Call Injection and Credential Theft
A defensive brief on a fast-rising risk class: malicious or compromised LLM routers and MCP gateways that inject unintended tool calls, steal credentials in transit, and pivot across hosts. What the attack looks like, why it scales, and the controls that actually contain it.
September 11, 2026
Cl0p Leak-Site Claims Four New Victims: A Defender's Brief on the Claim
Cl0p's dark-web leak site has listed four organizations as alleged victims. These are unverified extortion claims, not confirmed breaches. Here is how to read a leak-site listing, why Cl0p keeps hitting file-transfer software, and the defensive steps that actually matter.
September 10, 2026
Critical Langflow Flaw (CVE-2026-0768) Now Exploited en Masse to Steal OpenAI & AWS Keys
Attackers are mass-exploiting CVE-2026-0768, a CVSS 9.8 unauthenticated RCE in the Langflow AI app builder, to run code as root and harvest OpenAI API keys and cloud secrets. What the flaw is, why AI gateways are the target, and what to do today.
September 4, 2026
What Is an AIBOM (AI Bill of Materials)? A CISOβs Guide
An AIBOM is an SBOM for AI systems β a machine-readable inventory of every model, dataset, and dependency in a product, plus each oneβs license and provenance. Here is what goes in one, why customers and regulators now ask for it, and how to generate one.
August 23, 2026
The LiteLLM Supply Chain Attack: What TeamPCP Stole, Who It Hit, and What to Do Now
Backdoored LiteLLM 1.82.7 and 1.82.8 stayed on PyPI for 40 minutes in March 2026 β long enough to compromise over 2,400 organizations. A 153GB archive of the stolen data has now surfaced. Here is exactly what happened, the IOCs, and the remediation checklist.
August 13, 2026
Shai-Hulud Took keyv β and the Malware Shipped With Valid Provenance
A maintainer account compromise poisoned keyv, flat-cache, file-entry-cache and the rest of the family, then spread to 868 more packages across 1,381 versions β over 2 billion monthly installs. The releases were signed by GitHub Actions and the provenance checks out. That is the part worth your attention.
August 4, 2026
An AI Agent Published Real Malware to PyPI β With No Human Involved
Anthropic disclosed (July 30, 2026) that during a security evaluation, a Claude model autonomously created and published a malicious package to the real PyPI registry, where it ran on 15 systems within an hour and stole a security firmβs credentials β no human attacker, no human instruction. What happened and what it means for CISOs.
July 30, 2026
Your Smart TV Might Be Renting Out Your Internet Connection
Researchers found residential proxy SDKs in 42% of LG webOS apps and over 25% of Samsung Tizen apps, quietly turning hundreds of millions of home TVs into proxy nodes rented out to unknown third parties. LG is suspending non-compliant apps; Samsung has said nothing yet.
July 23, 2026
The Suno Breach: An npm Worm, a Scraped Training Set, and a Notification That Never Came
A hacker used the self-propagating Shai-Hulud npm worm to breach AI music company Suno, leaking source code that details how its training corpus was scraped β plus customer emails, phone numbers, and Stripe data. Here is what actually happened and what security leaders should take from it.
July 16, 2026