View Ridge Security
Back to Cyber HoseThreat Research & Deep Dives

TeamPCP Trivy Compromise Led to Malicious LiteLLM Releases

πŸ•΅οΈ RESEARCH & DEEP DIVES

  • TeamPCP Trivy Compromise Led to Malicious LiteLLM Releases
    TeamPCP used compromised Trivy access to publish malicious LiteLLM releases.

    • LiteLLM users and CI/CD pipelines worldwide were exposed, with more than 2,500 organizations potentially affected.
    • LiteLLM versions 1.82.7 and 1.82.8 were maliciously published to PyPI on March 24 and remained available for about 40 minutes.
    • Compromised Trivy tooling exposed LiteLLM’s PyPI publishing token, which attackers used to upload the releases outside the official CI/CD workflow.
    • A litellm_init.pth startup hook harvested environment variables, SSH and cloud credentials, Kubernetes tokens, database passwords, and AI API keys.
    • Stolen data was encrypted and sent to models.litellm[.]cloud.
      πŸ“„ Source: github.com Β· πŸ“Ž Coverage: reddit.com Β· πŸ‘ via r/cybersecurity
  • Iranian Intelligence Targets Israeli Journalists With WhatsApp and Telegram Phishing
    Iranian intelligence is targeting Israeli journalists with phishing attacks.

    • Israeli journalists, including Haaretz reporters, are being targeted.
    • Attackers seek political and security information, journalistic sources, and working materials.
    • Operatives impersonate known entities or fellow reporters on WhatsApp and Telegram.
    • Personalized messages offer interviews, cooperation, or exclusive material before directing targets to malicious links or fake login pages.
    • The links can steal credentials, compromise Google accounts, and take over mobile phones.
      πŸ“Ž Coverage: haaretz.com Β· πŸ‘ via @metacurity@infosec.exchange
  • AppFlowy Cloud Exposes Authenticated SQL Injection in qcuiknote
    AppFlowy Cloud has a high-severity authenticated SQL injection in qcuiknote.

    • Self-hosted AppFlowy Cloud deployments are affected.
    • The qcuiknote feature is vulnerable to SQL injection, tracked as CVE-2026-16007.
    • Authenticated users with qcuiknote access can inject arbitrary SQL queries.
    • Successful exploitation can exfiltrate data from the underlying SQL database.
    • The vulnerability has a CVSS 4.0 score of 7.1.
      πŸ“Ž Coverage: projectblack.io Β· πŸ‘ via r/netsec

πŸ“‹ ADVISORIES

  • πŸ“„ Source for France’s DGFiP confirms taxpayer data theft affecting 678,000 users β€” presse.economie.gouv.fr

  • πŸ“„ Source for HoneyMyte Adds Signed Windows Kernel Rootkit to CoolClient Backdoor β€” securelist.com

πŸ”“ CVEs & KEV

  • CVE-2026-74845 β€” CVSS 8.7 β€” 2100 Technology|Official Document Management System - Arbitrary File UploadOf...

  • CVE-2026-74578 β€” CVSS 7.1 β€” crypto: algif_skcipher - force synchronous processing on trees without ctx->s...

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check