The TeamPCP hacking group continues its supply-chain rampage, now compromising the massively popular "LiteLLM" Python package ...
After hacking Trivy, TeamPCP moved to compromise repositories across NPM, Docker Hub, VS Code, and PyPI, stealing over 300GB ...
TeamPCP strikes again, with almost identical code to LiteLLM.
The threat group's shift to speedy attacks on AWS, Azure, and SaaS instances shows organizations need to respond quickly to ...
TeamPCP is exploring ways to monetize the secrets harvested during supply chain attacks, with identified ties to the Lapsus$ ...
The compromised packages, linked to the Trivy breach, executed a three‑stage payload targeting AWS, GCP, Azure, Kubernetes ...
With almost 175,000 npm projects listing the library as a dependency, the attack had a huge cascade effect and shows how ...
LangChain and LangGraph have patched three high-severity and critical bugs.
LiteLLM, a massively popular Python library, was compromised via a supply chain attack, resulting in the delivery of ...
CNCF launches Dapr Agents v1.0 at KubeCon EU, prioritizing crash recovery and durability over intelligence. Zeiss validates ...
LangChain and LangGraph have patched three high-severity and critical bugs.
On the morning of March 24, 2026, tens of thousands of software developers working on AI applications were unknowingly exposed to malware.