frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

The Trivy Supply Chain Attack Reached LiteLLM

https://grith.ai/blog/litellm-compromised-trivy-attack-chain
3•edf13•2h ago

Comments

edf13•1h ago
Author here. The point of this post is not “LiteLLM was compromised” since that was already covered on HN, but the chain behind it.

We tried to connect the February 27, 2026 Trivy CI compromise to the later Trivy release/tag issues, the trivy-action poisoning, the npm/Checkmarx follow-on activity, and finally the LiteLLM 1.82.7/1.82.8 package on March 24 2026!

What made it look like one campaign to us was the repeated overlap in operator attribution, payload structure, and artifacts like tpcp.tar.gz, plus the LiteLLM maintainer saying it appears to have come from Trivy in their CI/CD.

If anyone spots gaps or overreach in the timeline, I’d be interested in corrections.

RustSec Integrity Breach Hides Dangerous Crypto Flaw

https://www.flyingpenguin.com/rustsec-integrity-breach-hides-dangerous-crypto-flaw/
1•upofadown•4m ago•0 comments

More frequent ejaculations may boost men's fertility, research suggests

https://www.theguardian.com/society/2026/mar/25/more-frequent-ejaculations-men-fertility-research
1•giuliomagnifico•5m ago•0 comments

Running an open-weight LLM locally on an Apple Watch

https://twitter.com/nobodywho_ai/status/2036759422135832779
2•pielouNW•6m ago•0 comments

I Let AI Plan My Seaside Break and Wound Up Swimming in the North Sea

https://www.wsj.com/lifestyle/travel/i-let-ai-plan-my-seaside-break-and-wound-up-swimming-in-the-...
1•thm•6m ago•0 comments

.apks are just .zips; semi-legally hacking software for orphaned hardware [video]

https://www.youtube.com/watch?v=P1kfuCkWo24
1•abadar•9m ago•0 comments

Claude Code Tips You Didn't Know

https://trigger.dev/blog/10-claude-code-tips-you-did-not-know
1•vinhnx•10m ago•0 comments

Understanding Safety Levels in Physical Units Libraries

https://mpusz.github.io/mp-units/HEAD/blog/2026/03/23/understanding-safety-levels-in-physical-uni...
2•aw1621107•11m ago•0 comments

Show HN: Open Agent Spec. Treat AI agents like typed functions not prompt chains

https://github.com/prime-vector/open-agent-spec
1•andrewvector•12m ago•0 comments

Startups Die. Ideas Don't

https://startups.rip/
2•FinnKuhn•12m ago•0 comments

Ask HN: How does one get rich in 2026?

2•roschdal•13m ago•0 comments

EU votes on US deal: commit to buy a lot and get tariffs in return

https://policy.trade.ec.europa.eu/news/joint-statement-united-states-european-union-framework-agr...
3•yread•13m ago•0 comments

Instagram for AI Agents

https://agentgramapp.com
2•AsafOz•13m ago•0 comments

ProPublica's union authorizes the first U.S. newsroom strike over AI protections

https://www.niemanlab.org/2026/03/propublicas-union-authorizes-the-first-u-s-newsroom-strike-over...
2•giuliomagnifico•14m ago•0 comments

Ask HN: Looking for programmers who don't use and don't want to use AI

2•Eliah_Lakhin•14m ago•0 comments

Epic Games lays off more than 1k amid slowing Fortnite engagement

https://apnews.com/article/epic-games-layoffs-fortnite-video-games-6a15e7c3f7916ecba10150a767295549
1•hlynurd•16m ago•0 comments

Show HN: Retrospective Online – Sprint Retros for dev teams

https://retrospectiveonline.com/
1•MiquelLHC•17m ago•0 comments

Using Horn's information types to craft better notes

https://writing.bobdoto.computer/crafting-the-information-you-capture-in-main-notes/
2•taurusnoises•19m ago•0 comments

What would you build with 2 extra hours every day?

https://www.indiehackers.com/post/what-would-you-build-with-2-extra-hours-every-day-a5e2e35354
1•Kiwihubai•19m ago•0 comments

Judge orders Afroman to pay half of court costs despite vindication [video]

https://www.youtube.com/watch?v=pRHpxlKfpkI
1•burnt-resistor•20m ago•1 comments

Slow Electricity: The Return of DC Power? (2016)

https://solar.lowtechmagazine.com/2016/04/slow-electricity-the-return-of-dc-power/
2•Siecje•20m ago•0 comments

Lazy Tmux – Lazy-loading tmux sessions with a tree view

1•Alchemmist•26m ago•0 comments

C++26: A User-Friednly assert() macro

https://www.sandordargo.com/blog/2026/03/25/cpp26-user-friendly-assert
1•jandeboevrie•26m ago•0 comments

Making encrypted Java traffic observable with eBPF

https://coroot.com/blog/java-tls-instrumentation-with-ebpf/
1•nikolay_sivko•27m ago•0 comments

AI Slop or quality storytelling? – Dune themed MCP Gateway tutorial [video]

https://www.youtube.com/watch?v=pLQCG31HSK8
1•orweis•27m ago•0 comments

Use a Sun Mouse Systems Optical Mouse on a PC (2009)

http://www.telltronics.org/hardware/SunMouse.html
1•robin_reala•28m ago•0 comments

Rewrite Skill

https://github.com/howardmann/rewrite
1•elephant_burger•29m ago•1 comments

Generalized Discrete Diffusion from Snapshots

https://arxiv.org/abs/2603.21342
1•GaggiX•29m ago•0 comments

Why AI hasn't caused a job apocalypse – so far

https://www.nature.com/articles/d41586-026-00883-4
1•danielmorozoff•29m ago•0 comments

Show HN: Coordinate converter in a single HTML file

https://redgridtactical.github.io/RedGridMGRS/tools.html
1•redgridtactical•29m ago•0 comments

Can a mouse be cloned indefinitely?

https://www.nature.com/articles/d41586-026-00945-7
2•danielmorozoff•30m ago•0 comments