Observed Signal · Mar 28, 2026 · Security Incident · Source: Ed Sim (IT/VC) · Impact: 4/5 · Sentiment: Negative
Anthropic Leak and LiteLLM Supply-Chain Hack Spotlight AppSec
A newsletter summarizing RSA 2026 highlights a pair of high‑profile AI security stories: Fortune reported leaked documents about Anthropic’s in-development model “Claude Mythos,” which Anthropic warned could pose “unprecedented cybersecurity risks,” and Snyk detailed a supply‑chain compromise of LiteLLM. Researchers attribute the LiteLLM incident to threat actor TeamPCP using an AI‑driven tool (hackerbot‑claw / openclaw) to automate targeting; a human developer, Callum McMahon at FutureSearch, first detected the compromise when a malicious payload caused a fork bomb. The author argues AI model releases expand both attack surface and defender opportunity, and RSA conversations favored a layered AppSec approach: LLM‑powered discovery plus deterministic verification and human oversight. Other RSA themes: agent identity/permissions, permission‑fatigue, social engineering rise, nation‑state activity, and accelerating platform consolidation and M&A dynamics in security.
Leak of a major provider's new model and a documented AI‑driven supply‑chain compromise signal material shifts in enterprise attack surface and defensive needs; implications affect vendor risk, AppSec tooling, and enterprise AI governance.
Track Anthropic Signals & Market Shifts in Real-Time
Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.
Key Takeaways & Evidence Grounding
- Fortune reported leaked documents indicating Anthropic’s Claude Mythos model (in testing) is considered by Anthropic to present unprecedented cybersecurity risks.
- Snyk published an analysis of a supply‑chain compromise affecting LiteLLM, showing wider dependency impact.
- Threat actor TeamPCP used an AI agent tool (hackerbot‑claw / openclaw) to automate the LiteLLM attack; a human developer (Callum McMahon at FutureSearch) first detected it via a fork‑bomb crash.
- RSA 2026 attendees and CISOs emphasized agent identity/permissions, permission fatigue, social engineering increases, and the need for layered security combining stochastic LLM discovery with deterministic verification and human judgment.
Connected Companies & Entities
5 Entities mappedOntology Mapping & Concepts
Related Market Signals & Shifts
Recent verified developments and strategic activity across this market segment.
AI Agents Enable Fully Autonomous Cyber Intrusions
An independent OSINT-based cyber threat analysis published 2026-05-30 documents five related incidents from late May 2026 that indicate a shift in attacker tradecraft: AI is moving from a human-accelerating tool to an autonomous operator and an exploitable attack surface. Notable cases include a Sysdig-documented Marimo notebook compromise (CVE-2026-39987, CVSS 9.3) where an LLM agent autonomously executed a multi-stage pivot and dumped an internal PostgreSQL database; ChatGPhish, a prompt-injection-style attack against ChatGPT’s renderer disclosed by Permiso Security; Wiz’s JINX-0164 supply-chain and dev-infrastructure attacks against crypto targets (macOS RATs, trojanized npm package @velora-dex/sdk); Rapid7’s unauthenticated-to-RCE chain in Gogs (CVSS 9.4, reported 2026-03-17) with a public Metasploit module and ~1,141 internet-exposed instances; and a KelpDAO/LayerZero bridge compromise illustrating off-chain verifier single points of failure. The author emphasizes reducing trusted dependencies, isolating credentials, runtime behavioral detection, and treating AI output as the start—not the end—of verification.
Claude Code Leak and Multiple AI Model Releases
Anthropic accidentally exposed roughly 512,000 lines of Claude Code TypeScript via a source-map in an npm package, making a 1,906-file codebase publicly downloadable and rapidly mirrored. The leak revealed that Claude Code’s entire capability surface is implemented as an MCP-style tool layer — every capability (including Computer Use) runs as an MCP server/tool — and that an unreleased autonomous background mode called KAIROS is compiled and feature‑flagged. The source also shows a three‑layer memory architecture, ~40 discrete, permission‑gated tools, 44 feature flags, internal model codenames (Fennec, Capybara, Numbat) and an ANTI_DISTILLATION_CC anti‑distillation subsystem that injects decoy tool definitions. The incident coincided with a separate axios npm supply‑chain compromise, raising immediate security and supply‑chain concerns and publishing a de‑facto blueprint for production MCP servers and attack vectors.
Zenity Labs: Attackers Weaponize Enterprise AI Infrastructure
Zenity Labs published research showing threat actors are actively exploiting vulnerabilities in enterprise AI infrastructure—particularly LiteLLM gateways—to hijack LLM endpoints, run offensive operations, and steal AI compute. Sensors across Zenity’s global AI threat network recorded thousands of real-world attack attempts, including same-day exploitation attempts against CVE-2026-40217 and campaigns targeting other LiteLLM flaws such as an admin-endpoint issue (CVE-2026-35029) patched by BerriAI and a novel SSRF variant related to CVE-2024-6587. Observed attacker behaviors included deploying autonomous pentesting tools (Strix) against live targets, routing multi-agent enterprise workflows through exposed infrastructure, and unintentionally exposing development artifacts via OpenAI’s Codex. Zenity’s co-founder and CTO Michael Bargury said the research reveals attacker TTPs and rapid exploitation timelines, and the company plans to publish additional findings.
Track Real-Time Market Signals & Shifts
Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.
