Bottom line: Over 2,500 organizations worldwide were breached due to the LiteLLM vulnerability.
What's happening: Trivy, a popular open-source vulnerability scanner, detected the malicious packages on GitHub before they were published by a group known as "S0m3x0r." The affected companies, primarily in the US and EU, were exposed to the vulnerability for an average of 18 days before the packages were published, with 95% of them exposed before the packages were published.
What to do: CISOs should immediately update their Trivy versions to 0.9.7 or later to prevent further breaches. Additionally, security teams should review their incident response plans to ensure they are prepared for similar attacks in the future.