A sophisticated supply chain attack by threat group TeamPCP, which initially compromised Aqua Security's Trivy open source vulnerability scanner, has expanded to Checkmarx's KICS static analysis tool and LiteLLM, an open source AI gateway. The attackers harvested GitHub personal access tokens and cloud credentials from CI/CD
Table of contents
A Moving TargetIncomplete Containment an IssueKeeping Under the RadarTeamPCP Worms Its Way InTargeting Open Source, AI DevelopmentSort: