← Journal

434,000 pipelines exposed in a 40 minute PyPI window

A compromised LiteLLM release scraped credentials from 434,000 CI/CD pipelines at over 2,500 organisations. The money is moving to the code change itself.

LiteLLM distributed two compromised versions through the Python Package Index for a 40 minute window in March. Forty minutes was enough: CloudSEK and Hudson Rock said this week that the code scraped machine memory, and that the exfiltrated data exposed credentials from 434,000 CI/CD pipelines at more than 2,500 organisations, among them Nvidia, Amazon Web Services, Samsung, Salesforce and Cisco (Ars Technica). The number worth sitting with is not 434,000. It is 40.

The blast radius is the build system

A package uploaded to a public index is pulled into builds automatically, which is what made a 40 minute window enough to reach thousands of organisations at once. What it reached is the part of those organisations that holds the keys to build and ship everything else. A stolen production password logs an attacker into one system; a stolen pipeline credential lets them into the place where software is assembled and signed before anyone downstream has a reason to look at it. That is the same mechanism running in the opposite direction, and it is why the count is measured in pipelines rather than in machines.

Discovery got cheaper for everyone at once

Microsoft shipped fixes for 419 vulnerabilities on 11 August, 62 of them rated critical and three of them zero-days, including CVE-2026-68820 already exploited by the Lazarus Group. That is about five times the volume the company patched in a typical month before AI-assisted bug discovery took hold (The Record). Read that as a capability statement rather than a security one. Finding flaws at machine speed is not a defender's advantage or an attacker's; it is a change in the cost of looking, and both sides got the discount in the same quarter.

The limit shows up one item later in the same day's record. Microsoft has no patch for ShieldBreak, a Windows Defender flaw that escalates a low-level user to full access on Windows 10, Windows 11 25H2 and Windows Server 2025, published by the researcher Nightmare Eclipse weeks after the company threatened them with legal action over earlier disclosures (TechCrunch). A patch pipeline running at five times its old rate and a disclosure relationship running through lawyers belong to one organisation. Volume is not the bottleneck any more. The handoff is.

The money is pricing the change, not the perimeter

This week's funding record reads like an answer to the same problem, and all three rounds land on the code change as the unit of risk.

  • CodeRabbit raised $143 million co-led by Atomico and Smash Capital at a $1.5 billion valuation, with BMW i Ventures and Datadog also in, a year after the AI code review company's $60 million Series B (Reuters).
  • Cytix raised a €6 million Series A led by Northern Gritstone for a platform that scores the security risk of each software change (EU-Startups).
  • Corma emerged from stealth with $60 million in seed funding led by Sequoia Capital, alongside Khosla Ventures and Coatue, to train AI models for defensive cybersecurity (Fortune).

A $1.5 billion valuation for reviewing diffs, and a Series A thesis that every individual change carries a score, are the market saying the interesting boundary is no longer the network edge. It is the commit, the dependency bump and the build that follows them.

What a 40 minute window costs

The three security items and the three rounds describe one system from two directions. Software now moves through public indexes and automated pipelines fast enough that a 40 minute mistake reaches 2,500 organisations, and flaws are found fast enough to produce 419 fixes in a month. Both facts come from the same acceleration. The one thing that has not sped up is the part where a human decides that a specific change is safe, which is precisely where an unpatched Defender escalation sat while its finder and its vendor talked to lawyers.

What the ledger holds

The record behind this note: Atomico and Sequoia Capital carry their funds and portfolio positions in one place, and the day-by-day feed is in the ledger. Every figure above links to the report it came from. Nothing here is estimated.

Built from the digest of 2026-08-13.