🔴 Breaking
CORRECTION: Trivy was primary vector — most LiteLLM breach victims never installed 1.82.7/1.82.8, one unrevoked token, 20 days, 76 of 77 trivy-action tags poisoned, audit from March 19  •  Taiwan AI swarm — nuclear safety agency, 4 days  •  LiteLLM rotate now — Trivy + KICS primary vectors  •  SharePoint CVE-2026-55040 — patch both CVEs  •  OpenAI Astra — first Critical classification   CORRECTION: Trivy was primary vector — most LiteLLM breach victims never installed 1.82.7/1.82.8, one unrevoked token, 20 days, 76 of 77 trivy-action tags poisoned, audit from March 19  •  Taiwan AI swarm — nuclear safety agency, 4 days  •  LiteLLM rotate now — Trivy + KICS primary vectors  •  SharePoint CVE-2026-55040 — patch both CVEs  •  OpenAI Astra — first Critical classification   
Trivy LiteLLM supply chain breach CVE-2026-33634 TeamPCP correction trivy-action tags 2026
Correction + UpdatePrimary Vector: Trivy20-Day Window76 of 77 Tags PoisonedAudit From March 19CVE-2026-33634 KEV

Trivy Was the Primary Vector: Most of 2,488 LiteLLM Breach Victims Never Installed 1.82.7 or 1.82.8 — One Unrevoked Token, 20 Days, 76 trivy-action Tags Poisoned — Re-Audit From March 19

SOCRadar confirmed: most organizations in the 153GB breach archive were exposed via the Trivy compromise beginning March 19 — not the 40-minute LiteLLM PyPI window on March 24. TeamPCP never targeted LiteLLM directly. One unrevoked automation token gave them write access to Trivy for ~20 days, poisoning 76 of 77 trivy-action version tags. Any CI/CD pipeline using tag-based Trivy references during that window had credentials harvested — regardless of LiteLLM usage. CVE-2026-33634 in CISA KEV. Pin Actions to commit SHAs. Verify token revocation completely.

Supply Chain · Trivy · CI/CD · CorrectionAugust 16, 202614 min read
Read Full Brief →
Threat Briefs
61
Active Threats
16
CISA KEV Listed
16
No Patch Yet
4
Latest

Threats & Attacks

Supply Chain · Trivy Primary Vector · Correction
Trivy Was Primary: Most LiteLLM Victims Never Installed 1.82.7/1.82.8 — Audit From March 19, Pin Actions to SHA

One unrevoked token → 20 days → 76 of 77 trivy-action tags poisoned. CI/CD pipelines using Trivy via tag references were compromised directly. LiteLLM packages were Stage 3, not Stage 1. CVE-2026-33634 KEV.

August 16, 2026
AI Security · Nation-State · Open-Source Tools
Taiwan AI Agent Swarm: Free Tools, Nuclear Safety Agency, 4 Days, 98.8% SSO Pivot, Guardrails Bypassed

8 agents, 12 waves, Hermes + OpenClaw (free). 21 systems, 85 accounts, 2,500+ records, nuclear safety, 7 energy firms. “The cost of running a competent attack has collapsed.”

August 15, 2026
Supply Chain · AI Infrastructure · Original Brief
LiteLLM Breach Original: 153GB, 2,488 Domains, AI API Keys — Read Article #61 for the Trivy Root Cause Correction

TeamPCP → Trivy → LiteLLM CI → malicious packages → 40 min PyPI. The 40-minute window was Stage 3. Most victims were hit at Stage 1. FBI active. Article #61 has the full correction.

August 13, 2026
SharePoint · CVSS 9.1 · AI-Found · Actively Exploited
SharePoint CVE-2026-55040: No Credentials, Any User, Full RCE — Trivy-Stolen Credentials Enable JWT Impersonation

Four JWT weaknesses. No auth. Admin impersonation. Chain to RCE. Trivy breach exposed the domain credentials that power this attack. Patch both CVEs now.

August 12, 2026
AI Security · First Critical Classification
OpenAI Pauses Astra: First-Ever Critical — May Independently Exploit Zero-Days in Hardened Systems

All prior models High. Astra Critical. Taiwan shows what that capability looks like deployed. Both confirmed in the same week.

August 10, 2026
AI Security · Atlassian · XPIA
Atlassian Rovo XPIA: All Jira/Confluence + SharePoint Data Exfiltrated — Web Search Bypass, 75 Days

Upload file → hidden instructions → Rovo URL retrieval → all data sent to attacker. No approval. Disabling web search doesn’t stop it. One route still unconfirmed closed.

August 9, 2026
Analysis

Intelligence & Deep Dive

The DataWater Intelligence Brief

Weekly CISO-level threat analysis — breaking vulnerabilities, technical depth, zero noise.