Wire
LiteLLM breach potentially touched 434K pipelines
CloudSEK says its reconstruction of the LiteLLM supply-chain cascade links potentially exposed data to more than 2,500 organizations and 434,000 CI/CD pipelines, though those figures do not prove every listed environment was compromised. LiteLLM’s incident notice confirms that versions 1.82.7 and 1.82.8 were live on PyPI for about 40 minutes, and Unit 42’s threat brief says the campaign targeted trusted developer and security tools. AI platform teams should inventory gateway dependencies and rotate credentials broadly after an exposure window, extending the archive’s runtime-security case for agent harnesses beyond the model boundary.