Trivy, Not LiteLLM Behind the 2,500 Org Compromise

Over 95% of the affected companies were exposed to malicious LiteLLM packages before their publication, according to a report by Cybrary.

Bottom line: Over 2,500 organizations worldwide were breached due to the LiteLLM vulnerability.

What's happening: Trivy, a popular open-source vulnerability scanner, detected the malicious packages on GitHub before they were published by a group known as "S0m3x0r." The affected companies, primarily in the US and EU, were exposed to the vulnerability for an average of 18 days before the packages were published, with 95% of them exposed before the packages were published.

What to do: CISOs should immediately update their Trivy versions to 0.9.7 or later to prevent further breaches. Additionally, security teams should review their incident response plans to ensure they are prepared for similar attacks in the future.

Source: SecurityWeek