Search Articles — Sudonull

Search Results

In this project

Attack on litellm: credentials theft in PyPI

https://sudonull.com/attack-on-litellm-credentials-theft-in-pypi

Details of litellm 1.82.7/1.82.8 compromise: collection of SSH keys, K8s secrets, exfiltration. Instructions for checking, removal, and rotation. Protect systems from TeamPCP.

Malicious npm package steals Polymarket bots keys

https://sudonull.com/malicious-npm-package-steals-polymarket-bots-keys

Learn about the attack via the sleek-pretty package in npm: theft of API keys and SSH backdoors for Polymarket developers. How to protect bots and wallets — read the risk analysis and recommendations.

Stealer in LiteLLM: key theft on Python startup

https://sudonull.com/stealer-in-litellm-key-theft-on-python-startup

Stealer of API keys, SSH, AWS discovered in LiteLLM 1.82.7/1.82.8. Activation on Python start. Recommendations for auditing and replacing keys for developers.

OpenSSH 10.3: security patches and new features

https://sudonull.com/openssh-10-3-security-patches-and-new-features

Learn about vulnerability fixes in ssh/sshd, support for IANA agents and new options in OpenSSH 10.3. Patches for ECDSA, scp and configuration. Update systems for protection.

Warpgate for SSH access with SSO and IaC

https://sudonull.com/warpgate-for-ssh-access-with-sso-and-iac

Learn how to implement Warpgate for centralized management of SSH/RDP/DB access. SSO via Keycloak, Terraform IaC, session audit without agents. For DevOps middle/senior.

Trending Now