← Back to all episodes
May 4, 2026 — #10

Signed by Claude, Written by a Worm

#10 · ~11 min · Curated by Asaf Nakash

0:00 / 0:00
Listen on: Spotify Apple Podcasts Amazon Music YouTube RSS

Stories This Week

Curator's Corner

The angle that stuck with me this week isn't about any single vulnerability. It's about what connects them.

TeamPCP's Mini Shai-Hulud compromised real packages from real publisher accounts. The package came from a legitimate source. There was no typosquat to catch, no misspelled name to flag. The green checkmark was genuine, and it was the weapon. Organizations that auto-update from trusted sources were exposed first, precisely because their trust was the most complete.

Copy Fail corrupts the page cache in memory while leaving the disk untouched. Your file integrity monitor reports clean. The verification mechanism itself is the blind spot. The more you trust your integrity tooling, the more invisible this attack becomes.

LiteLLM has now been hit twice in six weeks. In March, TeamPCP's supply chain worm compromised it. In May, a pre-auth SQL injection (CVE-2026-42208) exposed the stored API keys to unauthenticated attackers. Different vulnerability classes, same infrastructure, same outcome. LiteLLM is the "AI keyring" that enterprises trust to centralize model access. That centralization of trust is exactly what makes it a high-value target.

📰 Get the full newsletter — every story, every source, every week