Apple Patched the Door. Attackers Used the Window.

macOS 26.4 added Terminal security scanning to block ClickFix attacks. Within 48 hours, Atomic Stealer was back, running through Script Editor instead. One click. No warning.

Read More

The AI Training Pipeline Just Became a High-Value Target

A trojanized LiteLLM package hit Mercor, the AI training vendor shared by OpenAI, Anthropic, and Meta, exposing the massive concentration risk in the AI supply chain.

Read More

TeamPCP's First Confirmed Victim Lost Passport Scans and Video Interviews

AI hiring platform Mercor confirmed a breach tied to the LiteLLM compromise. The stolen data includes passport scans and video interviews you can't exactly rotate like a password.

Read More

TeamPCP Is Back. Now It's Deploying Ransomware Through Your AI Libraries.

The supply-chain group that poisoned Trivy last week just hit LiteLLM and the Telnyx SDK, hid their payload in WAV audio files, and announced a ransomware affiliate partnership.

Read More

The Trivy Domino: How One Poisoned Security Tool Spread to a Thousand Cloud Environments

A poisoned Trivy Docker image grew into one of the year's worst CI/CD compromises. Thousands of pipelines ran the payload, LiteLLM got backdoored on PyPI, and the attackers built a three-part kit designed to hit Kubernetes clusters and stay.

Read More