Search: #SupplyChain

  1. 🔴 Apifox 被投毒

    Forwarded from 层叠 - The Cascading
    🔴 Apifox 被投毒。用户数据可能泄漏。

    - Apifox 是一个 API 管理与测试平台。
    - Apifox 的用户统计代码 CDN 在 3/4 后被投毒 [2],现已恢复至原来版本。
    - 根据文章分析 (LLM?),payload 会收集用户设备上的敏感信息及 Apifox 云服务凭据等,也可能造成其它种类的危害。
    - 托管 payload 的 C2 服务域名为 apifox.it.com;现已停止解析。

    rce.moe/~

    1. web.archive.org/~

    linksrc: https://t.me/renbaoshuo/1058

    #Security #Apifox #SupplyChain

  2. 🔴 LiteLLM 被骇,用户数据可能泄漏

    Forwarded from 层叠 - The Cascading
    🔴 LiteLLM 被骇,用户数据可能泄漏。

    受影响版本是 1.82.7 及 1.82.8。

    gh:BerriAI/litellm#24512
    seealso: HackerNews:47501729

    linksrc: https://t.me/bupt_moe/2676

    #Security #LiteLLM #SupplyChain