Mercor says it was hit by cyberattack tied to compromise LiteLLM

techcrunch.com

150 points by jackson-mcd 5 days ago


nope1000 - 3 days ago

> The incident also prompted LiteLLM to make changes to its compliance processes, including shifting from controversial startup Delve to Vanta for compliance certifications.

This is pretty funny.

The leaked excel sheet with customers of Delve is basically a shortlist of targets for hackers to try now. Not that they necessarily have bad security, but you can play the odds

robshippr - 3 days ago

Second major supply chain compromise in a week after the axios npm attack. 40 minutes and 500k machines affected. SOC2 won't catch this. The real question is whether your CI pipeline would have flagged a dependency change that happened between your last build and the one going to prod. Most teams have no visibility into that window at all.

CafeRacer - 3 days ago

I am genuinely wonder if anyone have had success landing gigs at Mercor.

sharadov - 3 days ago

Could not happened to a more usurious company.

aservus - 3 days ago

This is a good reminder that any tool handling sensitive data — even internal ones — needs to be transparent about where data goes. The assumption that SaaS tools protect your data is getting harder to defend.

cat-whisperer - 3 days ago

all leaks are tied together

signalflow - 3 days ago

[flagged]

Adam_cipher - 3 days ago

[flagged]

Chepko932 - 3 days ago

[dead]

tazsat0512 - 3 days ago

[dead]

signalflow - 3 days ago

[flagged]

devcraft_ai - 3 days ago

[flagged]

techpulselab - 3 days ago

[flagged]

n1tro_lab - 3 days ago

[flagged]

ashishb - 3 days ago

[flagged]