Whose code is your AI running? That's the question
When I wrote that article last week about AI agents independently releasing games, I was still excited by the idea that machines could complete the entire pipeline on their own. Today, seeing CloudSEK's report gave me chills. Over 2,500 companies, numerous CI/CD pipelines, and an open-source Python package called LiteLLM were poisoned, directly piercing through the AI supply chain. This isn't some minor incident from a small edge-case vendor; it's a major event where even Meta got hit.
Physix Frontier