Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
20MAY

LiteLLM SQL injection hits in 36 hours

3 min read
09:58UTC

UNC6780 exploited LiteLLM CVE-2026-42208 within 36 hours of the KEV addition, compressing the defender's patch window to roughly one-sixth of the typical enterprise cycle and pulling AWS keys and GitHub tokens out of the open-source LLM proxy.

TechnologyDeveloping
Key takeaway

UNC6780 breached LiteLLM 36 hours after its KEV addition, the same cluster that took Cisco AI Defense source.

UNC6780 exploited CVE-2026-42208, an SQL injection vulnerability in the open-source LiteLLM proxy library, within 36 hours of CISA adding the flaw to the KEV catalogue on Friday 8 May 2026, per Google's Threat Intelligence Group (GTIG) 1 2. LiteLLM is an open-source proxy that sits between enterprise applications and frontier Large Language Models; its commercial parent, BerriAI, was named as a victim of the same intrusion. UNC6780 used SANDCLOCK-stolen AWS keys and GitHub tokens to operate inside both estates.

The 36-hour figure matters because the typical enterprise patch cycle for KEV-flagged vulnerabilities runs five to ten days. GTIG's assessment is that this window has been compressed by roughly 85 percent for the LiteLLM case, leaving most defenders without a credible response interval between detection and active intrusion. The 36-hour figure runs alongside the deadline-before-patch tension established by Palo Alto's PAN-OS captive-portal flaw two days earlier , where the first federal deadline preceded the vendor's first available fix.

UNC6780 is the same cluster GTIG named in the Cisco AI Defense source-code theft. The AI-security M&A market repriced by the $32 billion Google-Wiz close in March 2026 now has named breach incidents on both sides of its supply chain: the defender (Cisco AI Defense) and the proxy layer most often deployed in front of it (LiteLLM and BerriAI). Cloudflare AI Gateway sits in the same architectural slot as LiteLLM and has not been named as a victim. For chief information security officers buying AI-security tooling, the procurement question shifts from feature comparison to supply-chain hygiene of the LLM proxy itself.

Deep Analysis

In plain English

LiteLLM is a popular open-source piece of software that lets applications talk to AI services like ChatGPT. Hackers found a security hole in it and started breaking in within 36 hours of the vulnerability being publicly announced, far faster than most organisations can deploy a fix.

Deep Analysis
Root Causes

LiteLLM's SQL injection in CVE-2026-42208 reflects a category of vulnerability common in libraries that receive rapid community contributions without mandatory security review gates.

The AI infrastructure tooling layer, proxies, gateways, and orchestrators, emerged faster than the software-supply-chain security practices governing it: no Software Bill of Materials requirement, no mandatory security audit before release to production, and no vendor-notified update channel for operators running self-hosted instances.

UNC6780's SANDCLOCK tooling, already used in the Trivy and Cisco GitHub operations (event-00), provided pre-positioned AWS keys and GitHub tokens that gave the cluster elevated access inside BerriAI's commercial infrastructure beyond the open-source library itself. The same credential-theft toolchain served three distinct targets within weeks.

First Reported In

Update #4 · AI joins the breach column on both sides

Google Threat Intelligence Group· 20 May 2026
Read original
Causes and effects
This Event
LiteLLM SQL injection hits in 36 hours
An AI-proxy library sitting between enterprises and frontier models was breached at machine speed. The cluster that took Cisco's defensive source code also runs the offensive side of the same AI-security market.
Different Perspectives
Group-IB
Group-IB
Group-IB, headquartered in Singapore, documented on 19 March that The Gentlemen began inside Qilin's own affiliate programme and split from it over a payment dispute. Its analysis makes this window's leak-site tally readable as a fracture inside one ransomware operation rather than the arrival of an unknown crew.
ENISA
ENISA
ENISA placed EU drinking water and wastewater in its cyber risk zone for the first time on 28 May, finding one in three water entities had never run a risk assessment. CISA's 30 July advisory to American operators reads as the operational sequel to a gap European regulators had already documented two months earlier.
House of Lords and NCSC
House of Lords and NCSC
The Cyber Security and Resilience Bill sits at House of Lords committee stage, its amendment paper running to 23 July. Separately, the NCSC guidance CISA cited when directing water operators to disconnect controllers is version 1.0 from March 2024, a two-year-old British document doing operational work in an American alert published last week.
heise online
heise online
heise online reported on 27 July that Russian state attackers, named as APT28, ran the hotel WiFi credential-harvesting campaign. Its attribution is firmer than ReliaQuest's own hedged low-to-medium confidence assessment of the same intrusion, a difference in national reporting posture rather than a settled dispute over who is responsible.
CISA and ReliaQuest
CISA and ReliaQuest
CISA compressed remediation deadlines under BOD 26-04 while, in the same window, telling water and wastewater operators to disconnect internet-exposed controllers rather than patch them. ReliaQuest, investigating the hotel WiFi campaign, held its assessment of the intrusion route at low-to-medium confidence and declined to name a state sponsor.
AIVD
AIVD
AIVD co-signed AA26-204A alongside CISA, the NSA and the FBI, adding its signature to the fifteen-agency coalition naming LAUNDRY BEAR. Dutch involvement continues a pattern of joint Five Eyes-adjacent advisories the agency has co-issued with CISA and NCSC through 2026.