{"generator":"GNU social 2.0.2-dev","title":"Conversation","totalItems":1,"items":[{"actor":{"id":"https:\/\/infosec.exchange\/users\/dangoodin","displayName":"Dan Goodin","status_net":{"avatarLinks":[{"url":"https:\/\/gnusocial.jp\/avatar\/92418-original-tmp20240105200742.webp","rel":"avatar","type":"image\/webp","width":400,"height":400},{"url":"https:\/\/gnusocial.jp\/avatar\/92418-96-20240105201020.webp","rel":"avatar","type":"image\/webp","width":96,"height":96},{"url":"https:\/\/gnusocial.jp\/avatar\/92418-48-20240105201020.webp","rel":"avatar","type":"image\/webp","width":48,"height":48},{"url":"https:\/\/gnusocial.jp\/avatar\/92418-24-20240105201020.webp","rel":"avatar","type":"image\/webp","width":24,"height":24}],"profile_info":{"local_id":"92418"}},"image":{"url":"https:\/\/gnusocial.jp\/avatar\/92418-96-20240105201020.webp","rel":"avatar","type":"image\/webp","width":96,"height":96},"objectType":"person","summary":"Reporter covering security at Ars Technica.  DM me on Signal: DanArs.82.","url":"https:\/\/infosec.exchange\/@dangoodin","portablecontacts_net":{"preferredUsername":"dangoodin","displayName":"Dan Goodin","note":"Reporter covering security at Ars Technica.  DM me on Signal: DanArs.82."}},"content":"<p>Wow, TeamPCP is hacking open-source developers faster than we can report on them. The latest (that I'm aware of, anyway) is LiteLLM. They worked with Trivy but didn't bother to change their credentials after Trivy was hacked, despite an ample amount of advice to do so.<\/p><p>Folks, if any of you used LiteLLM, now is the time to change your credentials, in an atomic way. Now, as in immediately.<\/p><p><a href=\"https:\/\/news.ycombinator.com\/item?id=47501729\" rel=\"nofollow\">https:\/\/news.ycombinator.com\/item?id=47501729<\/a><\/p>","generator":{"id":"tag:gnusocial.jp,2026-07-31:notice-source:ActivityPub","objectType":"application","status_net":{"source_code":"ActivityPub"}},"id":"https:\/\/infosec.exchange\/users\/dangoodin\/statuses\/116285175398594132","object":{"id":"https:\/\/infosec.exchange\/users\/dangoodin\/statuses\/116285175398594132","objectType":"note","content":"<p>Wow, TeamPCP is hacking open-source developers faster than we can report on them. The latest (that I'm aware of, anyway) is LiteLLM. They worked with Trivy but didn't bother to change their credentials after Trivy was hacked, despite an ample amount of advice to do so.<\/p><p>Folks, if any of you used LiteLLM, now is the time to change your credentials, in an atomic way. Now, as in immediately.<\/p><p><a href=\"https:\/\/news.ycombinator.com\/item?id=47501729\" rel=\"nofollow\">https:\/\/news.ycombinator.com\/item?id=47501729<\/a><\/p>","url":"https:\/\/infosec.exchange\/@dangoodin\/116285175398594132","status_net":{"notice_id":null}},"to":[{"objectType":"http:\/\/activitystrea.ms\/schema\/1.0\/collection","id":"http:\/\/activityschema.org\/collection\/public"}],"status_net":{"conversation":"tag:gnusocial.jp,2026-03-24:objectType=thread:nonce=6c0b90f7aec1b6e9","notice_info":{"local_id":"12344361","source":"ActivityPub"}},"published":"2026-03-24T18:17:06+00:00","provider":{"objectType":"service","displayName":"GNU social JP","url":"https:\/\/gnusocial.jp\/"},"verb":"post","url":"https:\/\/infosec.exchange\/@dangoodin\/116285175398594132"}],"links":[{"url":"https:\/\/gnusocial.jp\/conversation\/6264490","rel":"alternate","type":"text\/html"}]}