A sophisticated supply chain attack by threat group TeamPCP, which initially compromised Aqua Security's Trivy open source vulnerability scanner, has expanded to Checkmarx's KICS static analysis tool and LiteLLM, an open source AI gateway. The attackers harvested GitHub personal access tokens and cloud credentials from CI/CD

5m read timeFrom devops.com
Post cover image
Table of contents
A Moving TargetIncomplete Containment an IssueKeeping Under the RadarTeamPCP Worms Its Way InTargeting Open Source, AI Development

Sort: