Loading…
Loading…
Tag
4 posts with this tag.
·9 min read
TeamPCP hijacked LiteLLM's build pipeline in March, exposing 2,500+ orgs. A 7-point self-audit if your team runs the open-source AI gateway.
·10 min read
A self-spreading worm compromised 57 npm packages in under 2 hours using binding.gyp instead of postinstall scripts, bypassing security scanners. What it means for teams that run npm install, and the 5 controls that limit your exposure.
·8 min read
Respond within 24 hours: AI vendor supply chain security checklist to map exposure, scope access, and contain a contractor breach like Vercel's.