On Thursday a 153 gigabyte archive of stolen credentials went public: 433,909 files, and reconstructed exposure across 2,488 corporate domains. Volkswagen is in it. So are John Deere, FedEx, Siemens, Samsung, Cisco and Deloitte. Nobody on that list was targeted. An attacker poisoned Trivy, a security scanner. LiteLLM, a free open-source gateway that routes a company's traffic to AI models, installed the poisoned scanner into its own automated build system. Two malicious versions of LiteLLM went to the public Python registry in March and stayed live for roughly forty minutes. That was long enough. In this episode, Stephen Forte covers: What was in the archive: cloud secret keys, Salesforce client secrets, Slack signing secrets and AI provider keys. Not passwords. The credentials a machine uses to act as the company. The caveat that makes the story stronger, not weaker. These are figures for exposure reconstructed from the archive, not confirmed breaches company by company. And many credentials carry no identifying information, so a company can be in the dataset with no practical way to find out. How it got in, and why a gateway is close to the worst thing on the list to poison. It sits in the path of every AI call, so it is trusted with every AI provider key. One component, all of the keys. Why this is not the story of a careless company. There was no purchase order, no vendor onboarding, no security questionnaire, no contract and nobody to call. That is how most of the AI stack arrived in most companies this year. The structural half, from Anthropic's Project Glasswing update: AI models pointed at more than a thousand open-source projects found 23,019 vulnerabilities, 6,202 of them high or critical, with 90 percent confirmed real where independently assessed. Then the other column. 530 disclosures to volunteer maintainers, 75 patches, 65 public advisories, and roughly two weeks to fix one. Twenty-three thousand found. Seventy-five fixed. The sentence Anthropic had no obligation to publish: some maintainers have asked them to slow down, because they need more time to design patches. Why finding software flaws has been industrialized and fixing them has not, and why that gap widens every quarter in the attacker's favour. A note on dates: the Glasswing data is from May and is stated as such on air. Sources: Help Net Security, "LiteLLM breach: stolen credentials leak," 2026-08-13. The 153GB archive, 433,909 files, 118,829 build-system dumps traced by Hudson Rock to 2,488 domains, the credential types, the named organizations, the exposure caveat, and the forty-minute window attributed to Hudson Rock's Alon Gal. SecurityWeek, "Over 2,500 Organizations Impacted by LiteLLM Supply Chain Attack," 2026-08-12. CloudSEK's separate count of roughly 434,000 files and close to 2,500 organizations. SC Media and NetSPI on the mechanism: TeamPCP compromised Aqua Security's Trivy scanner, and LiteLLM's automated build pipeline installed the compromised version, injecting malicious code into LiteLLM 1.82.7 and 1.82.8. LiteLLM security update and remediation, v1.83.0 with a rebuilt release pipeline. Anthropic, "Project Glasswing: An initial update," 2026-05-22. 23,019 vulnerabilities across 1,000-plus projects, 6,202 estimated high or critical, 1,752 independently assessed at 90.6 percent true-positive, 530 disclosed, 75 patched, 65 advisories, and the statement that some maintainers asked Anthropic to slow its disclosure rate. Previous episode referenced: s1e127, "Four Labs, One Vendor, Same Failure," 2026-08-11. The AI Brief from the YPO Technology Network is a daily executive briefing on the AI developments that matter to business leaders. Hosted by Stephen Forte.