PulseAugur
中
实时 04:17:06
English(EN) TeamPCP/UNC6780 poisoned Trivy to compromise LiteLLM on PyPI, leading to six enterprise breaches and 2,500+ organizations exposed via stolen CI/CD credentials.

通过 Trivy 和 LiteLLM 的供应链攻击暴露 2,500 多个组织

一项复杂的供应链攻击已被揭露,其中威胁行为者 TeamPCP 和 UNC6780 损害了 Trivy 漏洞扫描器。此次损害使他们能够将恶意代码注入 Python 包索引 (PyPI) 上的 LiteLLM 包。此次攻击导致六起企业泄露事件,并暴露了超过 2,500 个组织的 CI/CD 凭证。 AI

影响 此次供应链攻击凸显了软件开发生命周期中的漏洞,可能影响 AI 开发工具和基础设施。

排序理由 该集群描述了一次供应链攻击,该攻击损害了软件工具和软件包,导致数据泄露。

在 Mastodon — mastodon.social 阅读 →

AI 生成摘要 · Google Gemini · 来自 1 个来源。 我们如何撰写摘要 →

通过 Trivy 和 LiteLLM 的供应链攻击暴露 2,500 多个组织

本文如何被排名

Signal score
0 / 100
Composite score across the factors below. Higher = stronger signal that this story matters right now.
Newsworthiness bucket
Tool
该集群描述了一次供应链攻击,该攻击损害了软件工具和软件包,导致数据泄露。
Source corroboration
Single-source cluster
Only one publisher covered this so far. Single-source stories can still rank when the publisher is high-authority, but they lack cross-source corroboration.
Topics
other
Editorial topic classification. Feeds into how the story surfaces on /topic/<slug> hub pages and into the per-entity coverage mix.
AI-industry relevance
High
Clearly on-topic for AI-industry coverage.
Story freshness
49 days old
Aged out of breaking-news scoring windows; ranking reflects the durable signal from the full source set.

完整方法见我们的编辑标准。

报道来源 [1]

  1. Mastodon — mastodon.social TIER_1 English(EN) · [email protected] ·

    TeamPCP/UNC6780 毒化 Trivy 以破坏 PyPI 上的 LiteLLM,导致六起企业泄露事件,2,500 多个组织通过被盗 CI/CD 凭证暴露。

    TeamPCP/UNC6780 poisoned Trivy to compromise LiteLLM on PyPI, leading to six enterprise breaches and 2,500+ organizations exposed via stolen CI/CD credentials. # Cybersecurity # AI https:// deafnews.it/en/article/teampcp unc6780-six-enterprise-breaches-from-trivy-to-litellm