More than 2,500 companies and approximately 434,000 CI/CD pipelines worldwide were potentially exposed in what is believed to be the largest supply-chain attack targeting AI infrastructure in 2026.
In March 2026, threat actor group Team PCP compromised LiteLLM, a widely used open-source AI gateway. CloudSEK Threat Intelligence subsequently reconstructed the victim exposure and is now sharing details of impacted organisations to help security teams identify potential exposure and take remedial action.
The affected LiteLLM packages were reportedly available through PyPI for only around 40 minutes. However, automated CI/CD environments can download and execute dependencies rapidly, allowing even a short-lived compromise to create prolonged security risk.
Among the information potentially accessible from affected environments were AWS, Google Cloud and Microsoft Azure credentials, SSH keys, Kubernetes tokens, CI/CD secrets, repository credentials, environment variables and LLM/API keys.
CloudSEK’s exposure dataset includes high-confidence matches associated with major global organisations including NVIDIA, Samsung Electronics, Cisco Systems, Siemens, S&P Global, ServiceNow, Deloitte, Vodafone, X Corp, Zscaler, FedEx, Volkswagen, Thales and London Stock Exchange Group, among others.
CloudSEK stresses that an exposure match does not automatically confirm successful compromise, data theft or malicious use of credentials. Organisations identified in the dataset should validate their exposure and investigate relevant systems.
The Threat May Outlive the Original Attack
The significance of the incident extends beyond the malicious package itself.
Once credentials are copied from an affected environment, removing the compromised software does not invalidate those credentials. According to CloudSEK’s analysis, stolen access can potentially be reused, sold or weaponized even after the malicious package has been removed, creating the possibility of downstream attacks weeks or months later.
The FBI also issued FLASH-20260702-01 on July 2, 2026, covering cybercriminal group TeamPCP, further highlighting the continuing security concern surrounding the campaign.
CloudSEK is sharing the exposure research openly so affected organisations can identify possible exposure, rotate credentials, investigate suspicious activity and harden their environments before compromised access is reused.
AI Infrastructure Is Becoming a High-Value Target
The LiteLLM incident also reflects a broader shift in cyberattacks.
AI gateways, MCP servers, agentic systems, vector databases and other AI infrastructure increasingly sit between sensitive corporate data, identities, cloud services and systems capable of taking action.
This makes AI infrastructure an attractive target for attackers seeking access beyond a single application. CloudSEK assesses that future attacks are increasingly likely to target the AI layer precisely because of how deeply it is connected to enterprise environments.
CloudSEK AIVigil: Continuous AI Attack Surface Monitoring
The growing attack surface around enterprise AI is the security problem CloudSEK AIVigil is designed to address.
AIVigil continuously discovers and monitors exposed AI infrastructure, MCP servers, leaked AI credentials, vector databases, agentic workflows and shadow AI. It combines CloudSEK’s cyber threat intelligence with AI exposure monitoring to help security teams identify exposed assets, credentials and attack paths before they develop into wider enterprise incidents.
Check Your Exposure
Organisations can use CloudSEK’s free exposure-checking tool to determine whether credentials associated with their environment appear in the identified dataset:
Free Exposure Checker: https://exposure.cloudsek.com/ai-supply-chain-incident
Full Research Report: https://www.cloudsek.com/blog/ai-supply-chain-breach-2500-companies-434000-cicd-pipelines
Full List Of Exposed Companies: TeamPCP CI/CD Secret Exposure — Check if your organisation is affected | CloudSEK
3X Surge in AI Agent Deployments Since 2025 Says Salesforce
Posted in Commentary with tags Salesforce on August 11, 2026 by itnerdSalesforce has released its 2026 Agentic Enterprise Index, which analyzes global AI usage data to uncover how businesses are deploying, using, and getting value out of AI agents.
The index shows enterprise adoption is scaling up, with the average number of AI agents activated per enterprise nearly tripling year-over-year. Based on data from 734 million completed AI tasks, businesses are shifting from basic AI chatbots to complex, multi-step automated workflows that deliver tangible ROI.
The findings come as 27.8% of large Canadian enterprises are actively adopting AI, according to Statistics Canada, raising the question of what effective agent deployment looks like in practice. Salesforce’s data provides key insights for Canadian organizations looking to move from AI experimentation to measurable business impact.
Insights from the report include:
You can read the report here: https://www.salesforce.com/news/stories/agentic-enterprise-index-insights-2026/
Leave a comment »