Apr 04, 2026 •
Data Leak
|
#AI training data
#Supply chain attack
#LiteLLM
A security breach at AI data vendor Mercor potentially exposed sensitive AI training data, including proprietary methodologies and competitive intelligence, imp...
Read Analysis →
Apr 04, 2026 •
Vulnerability
|
#LiteLLM
#Supply-chain attack
#AI Training Data
AI training startup Mercor suffered a supply-chain attack leveraging the open-source tool LiteLLM, a software layer for managing large language model integratio...
Read Analysis →
Apr 04, 2026 •
Malware
|
#Claude AI
#Malware
#Supply Chain Attack
Threat actors are weaponizing leaked Anthropic Claude AI source code by embedding malware, disguised as legitimate repositories, and distributing it to develope...
Read Analysis →
Apr 04, 2026 •
Data Leak
|
#LiteLLM
#Supply Chain Attack
#Data Breach
AI training startup Mercor experienced a data breach resulting from a supply chain attack that leveraged the open-source project LiteLLM, impacting potentially ...
Read Analysis →
Apr 03, 2026 •
Malware
|
#LiteLLM
#Supply Chain Attack
#Malicious Code Injection
Attackers executed a supply-chain attack on the open-source library LiteLLM by exploiting stolen credentials to inject malicious code into its PyPI distribution...
Read Analysis →
Apr 03, 2026 •
Data Leak
|
#Mercor
#Security Breach
#AI Companies
The provided article content is empty, preventing a detailed technical summary. However, the title indicates Mercor has suffered a major security breach affecti...
Read Analysis →
Apr 03, 2026 •
Data Leak
|
#AI Training Data
#Supply Chain Security
#Third-Party Risk
A security incident at AI data vendor Mercor exposed proprietary AI training data methodologies and strategies from Meta and other major AI labs. This breach re...
Read Analysis →
Apr 03, 2026 •
Vulnerability
|
#CVE-2026-35616
#Zero-Day
#FortiClient EMS
A zero-day vulnerability (CVE-2026-35616) affecting FortiClient EMS has been actively exploited, necessitating the urgent release of emergency hotfixes. This cr...
Read Analysis →
Apr 03, 2026 •
Data Leak
|
#LiteLLM
#Supply Chain Attack
#Lapsus$
AI firm Mercor confirmed a breach stemming from a supply chain attack involving the open-source LiteLLM PyPI package, where attackers published malicious versio...
Read Analysis →
Apr 03, 2026 •
Data Leak
|
#Data Breach
#AI Model Training Data
#Third-Party Vendor
A major security incident impacting Mercor, a leading data vendor, potentially exposed proprietary AI model training data from several major AI labs, including ...
Read Analysis →
Apr 02, 2026 •
Vulnerability
|
#LLM Model Extraction
#Model Inversion
#RAG Retrieval Abuse
The article details advanced model theft and extraction techniques targeting Large Language Models (LLMs), enabling adversaries to replicate proprietary model b...
Read Analysis →
Apr 02, 2026 •
Vulnerability
|
#Prompt Injection
#LLM Jailbreak
#Large Language Models
Prompt injection and LLM jailbreaks are critical vulnerabilities in generative AI systems that allow attackers to override model instructions, bypass safety con...
Read Analysis →
Apr 02, 2026 •
Vulnerability
|
#Prompt Injection
#Data Poisoning
#OWASP LLM Top-10
The article highlights prompt injection as a leading risk for LLM applications, enabling attackers to override instructions, exfiltrate sensitive data from cont...
Read Analysis →
Apr 02, 2026 •
Vulnerability
|
#Prompt Injection
#Data Poisoning
#OWASP Top 10 for LLMs
The article outlines a comprehensive AI security roadmap addressing unique threats to LLMs and AI agents, such as prompt injection, data poisoning, model invers...
Read Analysis →
Apr 02, 2026 •
Vulnerability
|
#Supply Chain Attack
#LiteLLM
#Software Integrity
Mercor was reportedly impacted by a supply chain attack involving the LiteLLM component, suggesting a potential compromise of software integrity or introduction...
Read Analysis →
Apr 02, 2026 •
Vulnerability
|
#LiteLLM supply-chain attack
#credential-stealing malware
#PyPI package poisoning
A widespread supply-chain attack, orchestrated by TeamPCP, injected credential-stealing malware into popular open-source projects like Trivy, KICS, LiteLLM, and...
Read Analysis →
Apr 02, 2026 •
Vulnerability
|
#Memory poisoning
#Indirect prompt injection
#Model Context Protocol (MCP)
Autonomous AI trading agents in 2026 were compromised by protocol-level vulnerabilities such as memory poisoning and indirect prompt injection, targeting their ...
Read Analysis →
Apr 02, 2026 •
Vulnerability
|
#Prompt Injection
#Permission Bypass
#Claude Code
A critical vulnerability in Anthropic's Claude Code allows for the bypass of its permission system's deny rules. This flaw can be exploited via AI-gen...
Read Analysis →
Apr 02, 2026 •
Data Leak
|
#Supply-chain attack
#LiteLLM
#Credential harvesting
A supply-chain cyberattack on the open-source LiteLLM library led to the planting of malicious code designed for credential harvesting. This incident resulted i...
Read Analysis →
Apr 01, 2026 •
Data Leak
|
#Mercor AI
#Lapsus$
#Data Breach
Mercor AI has officially confirmed a significant data breach. This incident follows claims by the Lapsus$ threat group of successfully exfiltrating 4TB of data ...
Read Analysis →