September 11, 2026
- Wiz scanned ~3,000 internet-facing LiteLLM gateways and found 9.6% accepted the documented example master key
sk-1234 or required no auth at all — which turns a post-auth root RCE via custom code guardrails (CVE-2026-59821) into an effectively pre-auth one. An MCP endpoint auth bypass (CVE-2026-59822) lets any Bearer token mint a valid session, was confirmed exploitable on hundreds of instances, was added to CISA KEV on 2 September, and Wiz saw it exploited in the wild on its honeypots. A pass-through endpoint with no URL validation enables cloud credential theft and was not assigned a CVE or fixed. Patches exist for the rest; the work was presented at DEF CON 34 (Wiz, The Hacker News).
· AI Infrastructure & Agent Security
in Four Hours to First Victim: AI Agents Ran a Global PaperCut Campaign
August 28, 2026
- Louis Michael Gaebler, 23, and Ruben Ian Thomson, 21, appeared in Perth Magistrates Court facing 14 combined offences over alleged membership in TeamPCP, the group behind the March 2026 compromises of open-source scanners Trivy and Checkmarx KICS and the AI gateway LiteLLM (The Hacker News). The AFP describes a syndicate that "created malicious open-source software to rob thousands of global businesses"; Krebs has the deepest account of the multi-year package-registry campaign and the US–Australian cooperation behind the arrests (KrebsOnSecurity).
· Supply Chain & Takedowns
in Australia Charges Two Over the TeamPCP Supply-Chain Spree
August 13, 2026
- Two malicious LiteLLM releases — traced to the earlier Trivy compromise — mapped potential exposure to 2,100+ organizations. The rogue PyPI packages sat live ~40 minutes in March but carried credential-stealing code that harvested cloud keys, SSH keys, Kubernetes tokens, and database passwords; CloudSEK's dataset was built from ~434,000 captured files, per The Hacker News and SecurityWeek. Kevin Beaumont, who confirmed the leak against multiple victim orgs, calls it a "massive supply chain" incident rooted in orgs adopting GenAI tooling without secrets hygiene. (discussion)
· AI & Model Security
in ShieldBreak Turns a "Patched" Defender Bug Back Into SYSTEM