<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #LiteLLM</title><description>Cybersecurity articles tagged #LiteLLM on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>TeamPCP Hackers Arrested in Australia Over Supply Chain Attacks</title><link>https://runtimerebel.com/blog/teampcp-hackers-arrested-in-australia-over-supply-chain-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/teampcp-hackers-arrested-in-australia-over-supply-chain-attacks</guid><description>Australian Federal Police arrest two men linked to TeamPCP, a cybercrime syndicate behind major software supply chain attacks and data extortion.</description><pubDate>Tue, 01 Sep 2026 02:41:36 GMT</pubDate><category>TeamPCP</category><category>Supply Chain Attack</category><category>Shai Hulud</category><category>GitHub</category><category>LiteLLM</category></item><item><title>TeamPCP Supply Chain Attack: Trivy Compromise Impacts 2,500 Orgs</title><link>https://runtimerebel.com/blog/teampcp-supply-chain-attack-trivy-compromise-impacts-2500-orgs</link><guid isPermaLink="true">https://runtimerebel.com/blog/teampcp-supply-chain-attack-trivy-compromise-impacts-2500-orgs</guid><description>A supply chain attack attributed to TeamPCP compromised over 2,500 organizations, primarily through Aqua Security&apos;s Trivy scanner, not LiteLLM.</description><pubDate>Sat, 15 Aug 2026 00:42:24 GMT</pubDate><category>TeamPCP</category><category>Trivy</category><category>LiteLLM</category><category>Supply Chain Attack</category><category>Shai Hulud</category></item><item><title>Malicious LiteLLM PyPI Releases Steal Cloud Credentials via TeamPCP</title><link>https://runtimerebel.com/blog/malicious-litellm-pypi-releases-steal-cloud-credentials-via-teampcp</link><guid isPermaLink="true">https://runtimerebel.com/blog/malicious-litellm-pypi-releases-steal-cloud-credentials-via-teampcp</guid><description>Malicious LiteLLM PyPI releases 1.82.7 and 1.82.8 exfiltrated cloud keys, SSH keys, and tokens from 2,100+ organizations in the TeamPCP supply chain campaign.</description><pubDate>Wed, 12 Aug 2026 09:02:31 GMT</pubDate><category>LiteLLM</category><category>PyPI</category><category>Supply Chain Attack</category><category>TeamPCP</category><category>Credential Theft</category></item><item><title>LiteLLM Proxy Server Takeover via Critical Vulnerability Chain</title><link>https://runtimerebel.com/blog/litellm-proxy-server-takeover-via-critical-vulnerability-chain</link><guid isPermaLink="true">https://runtimerebel.com/blog/litellm-proxy-server-takeover-via-critical-vulnerability-chain</guid><description>Researchers at Obsidian Security have identified a three-vulnerability chain in LiteLLM that allows low-privilege users to gain full server control.</description><pubDate>Mon, 15 Jun 2026 17:44:24 GMT</pubDate><category>LiteLLM</category><category>Obsidian Security</category><category>AI Gateway</category><category>Privilege Escalation</category><category>RCE</category></item><item><title>CVE-2026-42271: BerriAI LiteLLM RCE Exploited in the Wild</title><link>https://runtimerebel.com/blog/cve-2026-42271-berriai-litellm-rce-exploited-in-the-wild</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-42271-berriai-litellm-rce-exploited-in-the-wild</guid><description>CISA warns of active exploitation of CVE-2026-42271 in BerriAI LiteLLM. This command injection flaw allows attackers to achieve RCE and compromise AI proxies.</description><pubDate>Tue, 09 Jun 2026 09:15:35 GMT</pubDate><category>CVE-2026-42271</category><category>LiteLLM</category><category>BerriAI</category><category>CISA KEV</category><category>RCE</category><category>Command Injection</category></item><item><title>LiteLLM Proxy Data Exposure &amp; Modification — Urgent Patch Required</title><link>https://runtimerebel.com/blog/litellm-proxy-data-exposure-modification-urgent-patch-required</link><guid isPermaLink="true">https://runtimerebel.com/blog/litellm-proxy-data-exposure-modification-urgent-patch-required</guid><description>Critical vulnerability in LiteLLM proxy enables unauthorized database read/modify access. Exploitation observed shortly after disclosure. Patch immediately.</description><pubDate>Wed, 29 Apr 2026 16:39:36 GMT</pubDate><category>LiteLLM</category><category>Data Exposure</category><category>LLM Security</category><category>Proxy Vulnerability</category><category>Database Access</category></item><item><title>CVE-2026-42208: Active Exploitation of LiteLLM SQL Injection</title><link>https://runtimerebel.com/blog/cve-2026-42208-active-exploitation-of-litellm-sql-injection</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-42208-active-exploitation-of-litellm-sql-injection</guid><description>Attackers are actively exploiting CVE-2026-42208, a critical SQL injection flaw in LiteLLM, within 36 hours of disclosure. Patch to prevent database compromise.</description><pubDate>Wed, 29 Apr 2026 08:52:44 GMT</pubDate><category>CVE-2026-42208</category><category>LiteLLM</category><category>BerriAI</category><category>SQL Injection</category></item><item><title>CVE-2026-42208: LiteLLM Pre-Auth SQLi Actively Exploited – Patch Now</title><link>https://runtimerebel.com/blog/cve-2026-42208-litellm-pre-auth-sqli-actively-exploited-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-42208-litellm-pre-auth-sqli-actively-exploited-patch-now</guid><description>Hackers are actively exploiting CVE-2026-42208, a critical pre-authentication SQL injection vulnerability in LiteLLM, to access sensitive data.</description><pubDate>Wed, 29 Apr 2026 00:51:59 GMT</pubDate><category>CVE-2026-42208</category><category>LiteLLM</category><category>SQL Injection</category><category>Pre Authentication</category><category>LLM Gateway</category></item><item><title>litellm 1.82.8 Supply Chain Compromise via Malicious .pth File</title><link>https://runtimerebel.com/blog/litellm-1-82-8-supply-chain-compromise-via-malicious-pth-file</link><guid isPermaLink="true">https://runtimerebel.com/blog/litellm-1-82-8-supply-chain-compromise-via-malicious-pth-file</guid><description>Security analysis of a supply chain compromise in litellm 1.82.8 on PyPI, where a malicious .pth file enables automatic code execution on Python startup.</description><pubDate>Wed, 08 Apr 2026 12:29:28 GMT</pubDate><category>LiteLLM</category><category>PyPI</category><category>Supply Chain Attack</category><category>Python</category><category>RCE</category></item><item><title>Mercor Hit by LiteLLM Supply Chain Attack – Lapsus$ Claims 4TB Data Theft</title><link>https://runtimerebel.com/blog/mercor-hit-by-litellm-supply-chain-attack-lapsus-claims-4tb-data-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/mercor-hit-by-litellm-supply-chain-attack-lapsus-claims-4tb-data-theft</guid><description>AI recruiting firm Mercor is investigating a LiteLLM supply chain attack, with Lapsus$ claiming to have stolen 4TB of sensitive data.</description><pubDate>Thu, 02 Apr 2026 12:29:10 GMT</pubDate><category>Mercor</category><category>LiteLLM</category><category>Lapsus</category><category>Supply Chain Attack</category><category>Data Theft</category><category>AI Security</category></item><item><title>TeamPCP Supply Chain: Checkmarx Wider Scope &amp; LiteLLM PyPI Compromise</title><link>https://runtimerebel.com/blog/teampcp-supply-chain-checkmarx-wider-scope-litellm-pypi-compromise</link><guid isPermaLink="true">https://runtimerebel.com/blog/teampcp-supply-chain-checkmarx-wider-scope-litellm-pypi-compromise</guid><description>An update on the TeamPCP supply chain campaign details wider Checkmarx impact, LiteLLM PyPI compromise, and a CISA KEV entry.</description><pubDate>Thu, 26 Mar 2026 20:16:14 GMT</pubDate><category>TeamPCP</category><category>Supply Chain Attack</category><category>Checkmarx</category><category>LiteLLM</category><category>PyPI</category><category>CISA KEV</category></item><item><title>Checkmarx KICS &amp; VS Code Plugin Targeted in Supply Chain Attack</title><link>https://runtimerebel.com/blog/checkmarx-kics-vs-code-plugin-targeted-in-supply-chain-attack</link><guid isPermaLink="true">https://runtimerebel.com/blog/checkmarx-kics-vs-code-plugin-targeted-in-supply-chain-attack</guid><description>TeamPCP exploited Checkmarx KICS, VS Code plugins, and LiteLLM in a supply chain attack targeting code scanners and AI libraries, indicating expanding threats.</description><pubDate>Wed, 25 Mar 2026 00:37:08 GMT</pubDate><category>TeamPCP</category><category>Checkmarx KICS</category><category>VS Code</category><category>LiteLLM</category><category>Supply Chain Attack</category></item><item><title>LiteLLM PyPI Supply Chain Attack: TeamPCP Steals Credentials</title><link>https://runtimerebel.com/blog/litellm-pypi-supply-chain-attack-teampcp-steals-credentials</link><guid isPermaLink="true">https://runtimerebel.com/blog/litellm-pypi-supply-chain-attack-teampcp-steals-credentials</guid><description>TeamPCP compromised the LiteLLM PyPI package, backdooring it to steal credentials and auth tokens from hundreds of thousands of devices.</description><pubDate>Wed, 25 Mar 2026 00:36:46 GMT</pubDate><category>LiteLLM</category><category>PyPI</category><category>TeamPCP</category><category>Supply Chain Attack</category><category>Credential Theft</category><category>Python Package</category></item><item><title>TeamPCP Backdoors LiteLLM 1.82.7–1.82.8 via CI/CD Compromise</title><link>https://runtimerebel.com/blog/teampcp-backdoors-litellm-1-82-7-1-82-8-via-ci-cd-compromise</link><guid isPermaLink="true">https://runtimerebel.com/blog/teampcp-backdoors-litellm-1-82-7-1-82-8-via-ci-cd-compromise</guid><description>TeamPCP threat actors compromised LiteLLM versions 1.82.7 and 1.82.8, deploying credential harvesters and Kubernetes lateral movement tools via CI/CD.</description><pubDate>Tue, 24 Mar 2026 20:18:30 GMT</pubDate><category>LiteLLM</category><category>TeamPCP</category><category>Supply Chain Attack</category><category>Python Security</category><category>Kubernetes</category></item></channel></rss>