Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
24JUL

LiteLLM SQL injection hits in 36 hours

3 min read
18:20UTC

UNC6780 exploited LiteLLM CVE-2026-42208 within 36 hours of the KEV addition, compressing the defender's patch window to roughly one-sixth of the typical enterprise cycle and pulling AWS keys and GitHub tokens out of the open-source LLM proxy.

TechnologyDeveloping
Key takeaway

UNC6780 breached LiteLLM 36 hours after its KEV addition, the same cluster that took Cisco AI Defense source.

UNC6780 exploited CVE-2026-42208, an SQL injection vulnerability in the open-source LiteLLM proxy library, within 36 hours of CISA adding the flaw to the KEV catalogue on Friday 8 May 2026, per Google's Threat Intelligence Group (GTIG) 1 2. LiteLLM is an open-source proxy that sits between enterprise applications and frontier Large Language Models; its commercial parent, BerriAI, was named as a victim of the same intrusion. UNC6780 used SANDCLOCK-stolen AWS keys and GitHub tokens to operate inside both estates.

The 36-hour figure matters because the typical enterprise patch cycle for KEV-flagged vulnerabilities runs five to ten days. GTIG's assessment is that this window has been compressed by roughly 85 percent for the LiteLLM case, leaving most defenders without a credible response interval between detection and active intrusion. The 36-hour figure runs alongside the deadline-before-patch tension established by Palo Alto's PAN-OS captive-portal flaw two days earlier , where the first federal deadline preceded the vendor's first available fix.

UNC6780 is the same cluster GTIG named in the Cisco AI Defense source-code theft. The AI-security M&A market repriced by the $32 billion Google-Wiz close in March 2026 now has named breach incidents on both sides of its supply chain: the defender (Cisco AI Defense) and the proxy layer most often deployed in front of it (LiteLLM and BerriAI). Cloudflare AI Gateway sits in the same architectural slot as LiteLLM and has not been named as a victim. For chief information security officers buying AI-security tooling, the procurement question shifts from feature comparison to supply-chain hygiene of the LLM proxy itself.

Deep Analysis

In plain English

LiteLLM is a popular open-source piece of software that lets applications talk to AI services like ChatGPT. Hackers found a security hole in it and started breaking in within 36 hours of the vulnerability being publicly announced, far faster than most organisations can deploy a fix.

Deep Analysis
Root Causes

LiteLLM's SQL injection in CVE-2026-42208 reflects a category of vulnerability common in libraries that receive rapid community contributions without mandatory security review gates.

The AI infrastructure tooling layer, proxies, gateways, and orchestrators, emerged faster than the software-supply-chain security practices governing it: no Software Bill of Materials requirement, no mandatory security audit before release to production, and no vendor-notified update channel for operators running self-hosted instances.

UNC6780's SANDCLOCK tooling, already used in the Trivy and Cisco GitHub operations (event-00), provided pre-positioned AWS keys and GitHub tokens that gave the cluster elevated access inside BerriAI's commercial infrastructure beyond the open-source library itself. The same credential-theft toolchain served three distinct targets within weeks.

First Reported In

Update #4 · AI joins the breach column on both sides

Google Threat Intelligence Group· 20 May 2026
Read original
Causes and effects
This Event
LiteLLM SQL injection hits in 36 hours
An AI-proxy library sitting between enterprises and frontier models was breached at machine speed. The cluster that took Cisco's defensive source code also runs the offensive side of the same AI-security market.
Different Perspectives
AIVD
AIVD
AIVD co-signed AA26-204A alongside CISA, the NSA and the FBI, adding its signature to the fifteen-agency coalition naming LAUNDRY BEAR. Dutch involvement continues a pattern of joint Five Eyes-adjacent advisories the agency has co-issued with CISA and NCSC through 2026.
CNCERT
CNCERT
China's national CERT was not party to AA26-204A and has previously argued that Western KEV-based advisories conflate demonstrated exploit capability with confirmed breach impact. It is expected to treat this fortnight's coalition-based Russia attribution as a Five Eyes-led exercise rather than an independently verified finding.
Russia
Russia
Moscow has not publicly responded to the AA26-204A attribution naming LAUNDRY BEAR as a Russian state-supported actor behind the Zimbra zero-click chain. Russian officials have consistently denied state involvement in prior Western cyber-attribution advisories, a pattern this fifteen-agency coalition is likely to meet with the same denial.
National Crime Agency
National Crime Agency
The NCA called the Woolwich Crown Court sentencing of Owen Flowers and Thalha Jubair Britain's largest-ever cybercrime prosecution. It expects continued pressure on Scattered Spider's UK-linked membership, alongside City of London Police's push for statutory Cyber Crime Risk Orders.
CISA
CISA
CISA co-led AA26-204A naming LAUNDRY BEAR and added five more flaws to KEV this fortnight, including a three-day Oracle EBS deadline, while absorbing a one-month detection-to-listing gap on FortiSandbox. It expects the risk-tiered BOD 26-04 model to hold even as a proposed $707m FY27 cut threatens the staffing behind it.
UK managed service providers and data centre operators
UK managed service providers and data centre operators
Newly brought into critical-infrastructure scope by the Cyber Security and Resilience Bill's Lords second reading, facing fines up to £17m or 4% of global turnover and a new near-miss reporting duty they did not previously carry. The sector moves from best-practice guidance to statutory exposure within this Parliamentary session.