Top stories.
- President Trump deputizes private-sector companies to target cybercriminals.
- The LiteLLM supply-chain attack exposed credentials belonging to thousands of organizations.
- CISA mandates urgent patch for actively exploited Cisco firewall vulnerability.
President Trump deputizes private-sector companies to target cybercriminals.
President Trump has signed a national security memorandum establishing a framework that allows private-sector companies to assist federal law enforcement in offensive hacking operations against transnational criminal organizations, CyberScoop reports. Under this directive, a federal coordination center will oversee “Participating Companies” as they conduct cyber surveillance and effects operations against these groups. The program requires strict vetting, adherence to existing laws such as the Computer Fraud and Abuse Act, and oversight to evaluate companies' technical proficiency. While some cyber experts welcome this as a significant shift in US cyber policy that stops short of full "hack back" authorization, others caution that it sets a risky precedent by expanding private sector involvement in offensive cybersecurity operations.
The LiteLLM supply-chain attack exposed credentials belonging to thousands of organizations.
A supply-chain attack on open-source AI library LiteLLM exposed terabytes' worth of credentials and other secrets belonging to thousands of organizations, Ars Technica reports. The incident took place in March 2026, when the TeamPCP criminal group inserted malicious code into the LiteLLM Python packages on PyPI, which were live for about 40 minutes. The full impact of the attack was unclear at the time, but researchers at CloudSEK and Hudson Rock have now obtained a copy of the data stolen during the attack. The researchers say the breach compromised over 434,000 CI/CD pipelines across nearly 2,500 organizations, including Microsoft, Amazon, Cisco, Samsung, and Salesforce. The exposed data includes active database passwords, API keys, SSH keys, cloud credentials, Kubernetes secrets, package publishing credentials, and more.
The researchers advise affected organizations to immediately audit their environments and rotate all accessible credentials, assuming they were exposed.
CISA mandates urgent patch for actively exploited Cisco firewall vulnerability.
Cisco has issued patches for an actively exploited vulnerability affecting its Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense operating systems, Cybersecurity Dive reports. The flaw, caused by improper error handling during HTTP request processing, allows unauthenticated, remote attackers to crash the firewalls by sending error-riddled requests, leading to denial-of-service.
The US Cybersecurity and Infrastructure Security Agency (CISA) has added the flaw to its Known Exploited Vulnerabilities catalog and ordered Federal agencies to apply fixes by tomorrow, August 14th.