التقنية سلبي تحليل ذكي آلي The Hacker News 12 آب 2026, 01:04

تسريب بيانات خطير: اختراق PyPI يؤثر على الآلاف

تم اكتشاف إصدارين ضارين من LiteLLM على PyPI في مارس، يحتويان على تعليمات برمجية لسرقة بيانات اعتماد. تشير تحليلات CloudSEK إلى أن أكثر من 2100 منظمة قد تعرضت للخطر بسبب هذا الاختراق.

Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations

لماذا يهم هذا الخبر؟

يُظهر هذا الحادث أهمية التدقيق المستمر في حزم البرامج مفتوحة المصدر والتحقق من سلامتها قبل التثبيت، بالإضافة إلى ضرورة وجود آليات قوية للكشف عن التهديدات والاستجابة للحوادث.

سياق الخبر

Two malicious LiteLLM releases sat on PyPI for about 40 minutes in March carrying credential-stealing code capable of harvesting cloud keys, SSH keys, Kubernetes tokens, database passwords, and other secrets from systems that installed them. Threat intelligence firm CloudSEK now says a dataset it obtained, built from roughly 434,000 files the attackers captured, maps potential exposure to more

فتح الخبر الأصلي
تغطية مرتبطة

المزيد من أخبار التقنية