Skip to main content

Share story

Security AI

Mercor Data Breach Tied to LiteLLM Supply Chain Attack Raises Concerns for Anthropic and AI Partners

AI recruiting platform Mercor has confirmed a data breach that security researchers linked to an attack on LiteLLM, an open source library widely used by AI application developers to interface with large language model APIs, raising concerns about the exposure of sensitive data across Anthropic and its partner ecosystem, Moneycontrol reported. LiteLLM is a popular abstraction layer that lets developers call models from Anthropic, OpenAI, Google, and other providers through a unified interface. Its broad adoption in AI application stacks means that a compromise of the library can potentially propagate across many downstream applications and the organizations that use them. Mercor, which uses AI to match candidates to technical roles and counts several AI labs and technology companies among its clients, said the breach affected customer data. The company confirmed the incident but did not disclose the full scope of what was accessed. The attack vector via a trusted open source developer tool follows the pattern of other high-impact supply chain incidents. Developers who have integrated LiteLLM into production systems are advised to audit their dependencies, review recent version changelogs for signs of unauthorized modification, and rotate any API keys or credentials that may have been accessible in affected environments. The incident adds to growing concern about the security posture of the AI application ecosystem, where rapid development and heavy reliance on open source tooling has sometimes outpaced security review practices. LiteLLM maintainers have not yet issued a public statement at time of reporting.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from Moneycontrol and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Security Capital
Security Capital

Reco raises $55M extension for enterprise AI agent security

Reco raised a $55M Series B extension, bringing its total funding to $140M, TechCrunch reported. The company's technology helps enterprises secure and govern AI agents across software-as-a-service environments, where businesses ar...

AI Capital
AI Capital

Relay raises $36M for AI communications used by frontline workers

Relay raised $36M to help businesses capture information from frontline work, SiliconANGLE reported. The startup develops cloud-hosted radio communicators powered by AI for frontline workers. Relay says its aim is to capture what ...

Capital Products
Capital Products

Ultraviolette raises US$85 million and plans US entry in 2027

Electric motorcycle maker Ultraviolette raised US$85 million in funding led by Yali Capital and TDK Ventures and says it plans to enter the US market in 2027, New Atlas reported. The capital will support manufacturing of its F77 a...

Products
Products

Kagi ends Orion development for Linux and Windows

Kagi announced it is ending development of its Orion browser for Linux and Windows to focus its small team on macOS and iOS. The company plans to release the Linux and Windows source code and provide details within the next 30 day...