Light

Episode #1092 Quiz

Restraint Abliteration
Date: 2026-08-18 | Length: 2.5 hrs | Episode page at twit.tv

About this episode

A LiteLLM supply-chain compromise infected Trivy, then poisoned LiteLLM 1.82.7/1.82.8 via a .pth startup hook that exfiltrated environment variables, cloud keys, SSH, Kubernetes, and CI/CD secrets from about 2,488 organizations. Mitigation requires immediate version auditing, aggressive credential revocation, logging review, egress filtering, and comprehensive rotation automation.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: According to the episode’s account of the LiteLLM supply-chain compromise, which two LiteLLM releases were identified as the malicious versions that organizations were told to audit for immediately?
Question 2: What mechanism did the malicious LiteLLM package use so that the payload executed as soon as the Python interpreter initialized, even if the library was never explicitly imported?
Question 3: What did the episode say the Trivy developers failed to fully revoke, creating a roughly three-week window in which attackers could force-push malicious code to third-party builds?
Question 4: In the Zoom vulnerability story, which screen-sharing feature was the vulnerable component that the researchers said contained the protocol flaw?
Question 5: According to the episode’s description of GRAM, how many dual-use categories were used in the experiments that produced the 16 possible on/off configurations?
Cancel