正在加载视频...

视频加载失败

LiteLLM hack summary: What is it, why it's smart to target it, and how it happened (so far)

156,320 次观看 • 6 个月前 •via X (Twitter)

22 条评论

solst/ICE of Astarte 的头像
solst/ICE of Astarte6 个月前

Another banger by TeamPCP Links: Github issue:

solst/ICE of Astarte 的头像
solst/ICE of Astarte6 个月前

Thread on cursed orange site

solst/ICE of Astarte 的头像
solst/ICE of Astarte6 个月前

nanobot impacted:

solst/ICE of Astarte 的头像
solst/ICE of Astarte6 个月前

The LiteLLM line using Trivy

solst/ICE of Astarte 的头像
solst/ICE of Astarte6 个月前

The original blog post that found it

solst/ICE of Astarte 的头像
solst/ICE of Astarte6 个月前

Great blog post by @safedepio

solst/ICE of Astarte 的头像
solst/ICE of Astarte6 个月前

Hermes PSA

solst/ICE of Astarte 的头像
solst/ICE of Astarte6 个月前

Timeline and IoCs by @ramimacisabird

solst/ICE of Astarte 的头像
solst/ICE of Astarte6 个月前

YouTube:

solst/ICE of Astarte 的头像
solst/ICE of Astarte6 个月前

Another great blog post here:

Precogs AI 的头像
Precogs AI6 个月前

We have written a detailed article about it:

solst/ICE of Astarte 的头像
solst/ICE of Astarte6 个月前

Nice one

mRr3b00t 的头像
mRr3b00t6 个月前

love this

Ac1d 的头像
Ac1d6 个月前

is this you or someone from Astarte?

Ac1d 的头像
Ac1d6 个月前

teampcp undercover?

Jacko ⚡️ 的头像
Jacko ⚡️6 个月前

Maybe someone should leek the package list of all those packages that use it. Then maybe consider a `pip blame --uninstall litellm`.

MAKVision 的头像
MAKVision6 个月前

"it's just a dependency" — last words before 50,000 production environments become someone else's lab rats.

👩🏻‍💻 JustAskPenny 的头像
👩🏻‍💻 JustAskPenny6 个月前

@grok what was the root cause to this issue.

JP Aumasson 的头像
JP Aumasson6 个月前

great explainer, thank you!

MiamiCanes 的头像
MiamiCanes6 个月前

Great breakdown, crazy how good these hackers are getting! 👨‍💻🔒

Zulfikar Ramzan (He / Him) 的头像
Zulfikar Ramzan (He / Him)6 个月前

Excellent breakdown. The attacker realized that by targeting the AI routing layer, they get the keys to the entire kingdom (OpenAI, AWS, Anthropic) in a single strike. The scariest part is how easily it slipped past legacy SCA tools because there was no CVE. We have to shift to analyzing the actual behavior of our dependencies. My team just open-sourced a CLI (wtmp) to hunt for exactly these types of zero-day credential harvesting mechanisms. Flashlight for your repos:

Unicity 的头像
Unicity6 个月前

Wrote this breakdown take a look

相关视频