litellm data exfiltration

there seem to be recent public disclosure of "hacked" companies, >2000 of them using litellm which had a security issue recently 1, 2

while the issue itself is problematic and shows how quickly supply chain attacks or "get a quick api" into your network (litellm offers to stream multiple llm providers as a proxy) - I see a huge difference in the reporting

  • hudsonrock looks like they try to squeeze out as much advertising as possible (biggest hack ever...) and showing "brandname.tld/robots.txt" as hacked employee credentials 3
  • cloudsek just helps you quickly identifying the issue without overadvertising their capabilities 4