Security
LiteLLM supply chain breach exposes 2,488 firms, 153GB of secrets
Hudson Rock maps the largest AI supply chain breach to date: LiteLLM compromise hits AWS, Samsung, Cisco and thousands more.
This edition was produced with artificial intelligence. Text and voice are generated automatically.
LiteLLM supply chain attack compromises thousands of enterprises, 153GB of secrets leaked
A sophisticated supply chain campaign orchestrated by the threat actor group TeamPCP has compromised LiteLLM, a widely adopted open-source AI proxy gateway, leading to the silent exfiltration of deep developmental secrets from thousands of CI/CD pipelines worldwide. The attack began with the compromise of the GitHub Actions pipeline for Trivy, a popular open-source vulnerability scanner. Because LiteLLM developers used Trivy in their own CI/CD pipeline, the poisoned scanner gained legitimate read access to their runner environment, allowing attackers to steal LiteLLM’s PyPI publishing tokens and publish malicious package versions 1.82.7 and 1.82.8. The payload used a .pth Python startup hook, executing the moment the Python interpreter initialized, regardless of whether the LiteLLM library was imported. The three-stage payload harvested environment variables, local configuration files, attempted lateral movement across Kubernetes clusters, and installed a persistent systemd backdoor.
Android NFC relay malware WindRelay combined with SpyNote drains victims in 13-minute calls
Group-IB has uncovered a new Android NFC relay malware called WindRelay, used alongside the SpyNote RAT to steal card data and relay it to attackers in real time. In one investigated incident, a fraudster impersonating a bank employee called a victim, instructed them to sideload SpyNote disguised as a legitimate app with Accessibility Service permissions, and then installed WindRelay without further interaction. The attacker used the banking app to take out a loan in the victim’s name, then instructed the victim to tap their payment card on the phone and enter their PIN. WindRelay turned the phone into a fraudulent contactless reader, relaying the live NFC exchange including transaction-specific authentication data to the attacker’s device, enabling purchases at a genuine payment terminal.
Android malware combo takes out loans and relays victims’ credit cards →
Lazarus Group exploits Windows kernel zero-day for five weeks in defense sector campaign
North Korean state-sponsored hackers targeted defense and aerospace professionals in France, Germany, India, and Brazil for at least five weeks using a Windows kernel zero-day, CVE-2026-68820, which Microsoft patched on August 11. The campaign, a wave of Operation Dream Job, used fake LinkedIn recruiter messages offering jobs at recognized companies to lure victims. The vulnerability is a use-after-free race condition in afd.sys, providing kernel read/write primitives and full SYSTEM-level privileges without user interaction. Check Point Research reported the flaw on July 28, Microsoft assigned the CVE on August 5, and CISA added it to its Known Exploited Vulnerabilities catalog on patch day with a federal remediation deadline of August 25.
Lazarus Group Hacked Defense Workers With Windows Kernel Zero-Day for Five Weeks →
Signal launches Automatic Key Verification with independent auditors to thwart man-in-the-middle attacks
Signal has introduced Automatic Key Verification, a new security feature providing users a way to ensure their encrypted chats have not been intercepted. The feature is part of a key transparency system using Cloudflare and Trail of Bits as trusted third-party independent auditors to verify conversation integrity. Signal software engineer Katherine Yen said the system provides the same assurance as manually verifying safety numbers, but without requiring an in-person meeting or secondary communication channel. The system ensures the association between a phone number or username and its public encryption key is globally consistent and transparent, protecting against scenarios where a key is swapped out without the owner’s knowledge, such as if a malicious party compromised Signal itself.
Signal adds new security feature to thwart man-in-the-middle attacks →
Researchers demonstrate coin-sized device that can hack a Boeing 737 in under 60 seconds
Security researchers have demonstrated that in less than 60 seconds, they could open a hatch on a plane’s exterior, plug in a coin-sized device, and redirect the aircraft’s autopilot or sabotage its flight plan. The research was conducted by a group of academic researchers who spent years testing this approach to aviation cybersecurity. Their method involves surreptitiously gaining physical access to a plane and plugging in a device designed to silently run the attackers’ malicious code, targeting high-value, offline computers the way spies and saboteurs have. The research highlights the vulnerability of aircraft systems that are not connected to the internet but remain physically accessible.