# LiteLLM

Type: Technology

Source: Cyber Intelligence Brief — https://getcyberbrief.com/entity/litellm
Canonical HTML page: https://getcyberbrief.com/entity/litellm

## Timeline

- **2026-09-02**: CISA adds flaw to KEV catalog — Agency catalogs CVE-2026-9586 with six other actively exploited vulnerabilities.
- **2026-09-01**: Horizon3 issues public warning — Security firm confirms CVE-2026-9586 exploitation in the wild and shares IoCs.
- **2026-08-30**: Honeypots record active exploitation — Horizon3 observes reverse-shell attempts from IP 176.65.148.184 and base64 exfiltration of process data.
- **2026-08-27**: Charges announced — AFP announces charges for computer hacking and money laundering, with Thomson facing up to 20 years per offense and Gaebler up to 5 years.
- **2026-08-26**: Arrests in Western Australia — Ruben Ian Thomson, 21, and Louis Michael Gaebler, 23, are arrested in Cottesloe and Mandurah; electronic devices seized for forensic analysis.
- **2026-07-14**: Sangoma ships Switchvox 8.4.0.2 — Vendor releases patches for all 12 reported vulnerabilities.
- **2026-04-10**: Horizon3 reports 12 Switchvox flaws to Sangoma — Researchers disclose CVE-2026-9586 and 11 other vulnerabilities to the vendor.
- **2026-04**: Investigation begins — AFP and FBI receive key information from cybersecurity firms and open a joint investigation into TeamPCP supply-chain attacks.

## Recent coverage (2 stories)

### 9.3 CVSS Switchvox Flaw Actively Exploited for Reverse Shells
2026-09-04 13:33:41 · Sentiment: Negative · Impact: 7/10 · Sources: 2

Sangoma Switchvox CVE-2026-9586, a 9.3 CVSS unauthenticated SQL injection flaw, has moved from patch advisory to active incident. Horizon3 honeypots caught reverse-shell attempts and process data exfiltration, and CISA KEV now tracks the bug. Security teams must patch to 8.4.0.2 or assume compromise on exposed VoIP systems.
Full story: https://getcyberbrief.com/story/cve-2026-9586-sangoma-switchvox-active-exploit-reverse-shell

### TeamPCP Arrests: 500K Credentials Stolen From 1,000+ Orgs
2026-08-27 14:03:33 · Sentiment: Positive · Impact: 6/10 · Sources: 2

Two alleged TeamPCP members face up to 20 years in prison after a supply-chain campaign that stole 500,000 credentials and 300GB from over 1,000 organizations via Trivy, KICS, and LiteLLM. The case underscores how compromised CI/CD pipelines became a data-harvesting network for extortion groups.
Full story: https://getcyberbrief.com/story/australia-arrests-teampcp-hackers-cyber

---
This page is a machine-readable summary. Sentiment measures the directional read of each development for this entity, not the tone of the reporting; impact weights consequence, not syndication reach. See https://getcyberbrief.com/guides/methodology for the full editorial methodology.