Zum Hauptinhalt springen
tsecurity.de LIVE
Echtzeit-Radar & Feeds
Alle RSS Feeds
👥 Community & Social
YouTube Security VideosGoogle Cloud Tech: Gemini is coming to your city(24.09.2026 um 15:00 Uhr)
AI & KI NachrichtenGoogle’s latest moonshot to put machine learning in space(24.09.2026 um 15:12 Uhr)
Windows Tipps & SecurityPoll: What's your favorite Surface of 2026?(24.09.2026 um 14:58 Uhr)
Sichere ProgrammierungStreaming Materialized Views for Live Read Models (2026)(24.09.2026 um 15:02 Uhr)
Sichere ProgrammierungA Day Is Not 86400 Seconds: The DST Bug in Your Date Math(24.09.2026 um 15:02 Uhr)
Sichere ProgrammierungSetting up Traefik: reverse proxy with automatic HTTPS(24.09.2026 um 15:02 Uhr)
Sichere ProgrammierungA 200 OK response does not prove a secret leak(24.09.2026 um 15:02 Uhr)
Sichere ProgrammierungHow hot do you like it?(24.09.2026 um 15:05 Uhr)
YouTube Security VideosGoogle Cloud Tech: Gemini is coming to your city(24.09.2026 um 15:00 Uhr)
AI & KI NachrichtenGoogle’s latest moonshot to put machine learning in space(24.09.2026 um 15:12 Uhr)
Windows Tipps & SecurityPoll: What's your favorite Surface of 2026?(24.09.2026 um 14:58 Uhr)
Sichere ProgrammierungStreaming Materialized Views for Live Read Models (2026)(24.09.2026 um 15:02 Uhr)
Sichere ProgrammierungA Day Is Not 86400 Seconds: The DST Bug in Your Date Math(24.09.2026 um 15:02 Uhr)
Sichere ProgrammierungSetting up Traefik: reverse proxy with automatic HTTPS(24.09.2026 um 15:02 Uhr)
Sichere ProgrammierungA 200 OK response does not prove a secret leak(24.09.2026 um 15:02 Uhr)
Sichere ProgrammierungHow hot do you like it?(24.09.2026 um 15:05 Uhr)
Intelligence View
⚡ tsecurity.de Intelligence

Urgent Security Alerts & Self-Hosted Swarm: Building Local LLM Infra Safely

Urgent Security Alerts & Self-Hosted Swarm: Building Local LLM Infra Safely Today's Highlights This week, critical security vulnerabilities hit popular local LLM tools LiteLLM and LM Studio, demanding immediate action from…

0
↗ Quelle (dev.to)
Reagiere als Erste:r — dein Feedback zählt!




Urgent Security Alerts & Self-Hosted Swarm: Building Local LLM Infra Safely






Today's Highlights



This week, critical security vulnerabilities hit popular local LLM tools LiteLLM and LM Studio, demanding immediate action from developers. Meanwhile, a new Docker Swarm manager, Komodo v2, promises to simplify self-hosted container orchestration.






Tell HN: Litellm 1.82.7 and 1.82.8 on PyPI are compromised (Hacker News)



Source: https://github.com/BerriAI/litellm/issues/24512



An urgent alert from the LiteLLM GitHub repository warns users that PyPI versions 1.82.7 and 1.82.8 of the litellm library have been compromised. The malicious package, disguised as litellm, contained obfuscated code designed to steal sensitive environment variables, particularly those prefixed with LLM_. This includes API keys and other credentials used for interacting with various large language models across different providers. The vulnerability was discovered and reported rapidly, leading to the affected versions being removed from PyPI.



For developers relying on litellm for unifying LLM API access, this is a critical supply chain security incident. The incident highlights the ever-present risks in open-source dependencies, especially those that handle credentials. Users who have installed these specific versions are strongly advised to take immediate action: check their pip installation history, downgrade to a known safe version (e.g., 1.82.6 or the latest uncompromised release), and rotate any API keys or credentials that might have been exposed. Vigilance remains paramount for all developers leveraging PyPI packages.



Comment: As someone running vLLM and interacting with multiple LLM APIs, this is a stark reminder to pin dependencies and audit pip installs rigorously. Definitely checking my LLM_ vars and rotating keys tonight across my self-hosted setup.






LM Studio possible infected with GlassWorm / type malware (r/selfhosted)



Source: https://reddit.com/r/selfhosted/comments/1s2g49f/lm_studio_possible_infected_with_glassworm_type/



A concerning report has surfaced on r/selfhosted and r/LocalLLaMA regarding potential malware infection in LM Studio, a popular desktop application for running local LLMs. Users have reported suspicious network activity, particularly connections to a Chinese IP address, leading to speculation that certain versions of LM Studio may be bundled with GlassWorm-type malware. This type of threat is known for persistent backdoor access and data exfiltration, making it a severe risk for developers who download and run local LLMs on their local machines.



While the exact scope and affected versions are still under investigation, the implications are profound for our community, who frequently download and experiment with cutting-edge models via tools like LM Studio. Users are strongly advised to exercise extreme caution: if you have recently downloaded or updated LM Studio, perform a thorough malware scan, monitor network activity, and consider isolating your local LLM development environment within a virtual machine or sandboxed container. It's a potent reminder to verify software sources and maintain strict network hygiene when running third-party executables.



Comment: Running local LLMs on an RTX 5090 is awesome, but this is a nightmare scenario. I'm air-gapping my dev machine from critical data until this is fully clarified and I've verified my installs.






Komodo 🦎 Container manager 🦎 v2: Docker Swarm (r/selfhosted)



Source: https://reddit.com/r/selfhosted/comments/1s2f17m/komodo_container_manager_v2_docker_swarm/



The self-hosting community is buzzing about the release of Komodo v2.0.0, a new container manager designed to simplify the deployment and management of Docker Swarm clusters. Komodo aims to provide a user-friendly interface and workflow for orchestrating containerized applications, a crucial capability for anyone building and maintaining their own self-hosted infrastructure. This update specifically focuses on enhancing Docker Swarm integration, making it easier for developers to leverage swarm mode for high availability, service discovery, and scaling on their own hardware.



Komodo isn't just another GUI; it promises features that address common pain points in self-hosted container deployments, such as simplified service configuration and monitoring. While detailed architectural decisions will be explored in future releases, the initial announcement highlights a commitment to robust management of services, networks, and volumes within a Swarm. For those running various services—from local LLM inference APIs to data pipelines—on their own hardware, a tool like Komodo could significantly streamline operations, reduce overhead, and make complex deployments more accessible. Developers eager to improve their self-hosted Docker Swarm experience should definitely check out the GitHub repository for installation instructions and to contribute to its development.



Comment: Finally, a potential self-hosted solution that makes Docker Swarm less of a headache for my local LLM services and background tasks. I'm always looking for better ways to orchestrate without needing full-blown Kubernetes on my custom infrastructure.

SOC Incident Playbook: Remote Code Execution (RCE) Defense
title: Detect Exploitation - Urgent Security Alerts & Self-Hosted Swarm: Building Local LLM Infra Safely
id: cd5877a0-7085-4828-8607-8f7ed3aa4fb7
status: experimental
description: Automatisch generierte SIEM-Erkennungsregel basierend auf CTI Intelligence
references:
  - https://tsecurity.de/
author: iShareStuff CTI Automated Detection Engine
date: 2026-09-24
logsource:
  category: network_connection
  product: any
detection:
  selection:
      CommandLine|contains:
        - 'exploit'
  condition: selection
falsepositives:
  - Legitime administrative Zugriffe oder Penetrationstests
level: high
tags:
  - attack.initial_access
rule CTI_Threat_Indicator {
    meta:
        author = "iShareStuff CTI Automated Detection Engine"
        date = "2026-09-24"
        description = "YARA Signature for "
    strings:
        $str = "Urgent Security Alerts & Self-" ascii wide
    condition:
        any of them
}
tsecurity.de Cognitive Threat RAG
Fokus-Vektor:

Kognitive Analyse für identifizierte Bedrohung: Erhöhte Bedrohungslage im Bereich Urgent Security Alerts & Self-Hosted Swa.... Basierend auf 368k Vektor-Korrelationen werden sofortige Isolationsmaßnahmen für betroffene Endpunkte empfohlen.

🛡️ Angriffsfläche & Exposure

Netzwerk/Remote-Zugriff ohne Vorauthentifizierung möglich.

Empfohlene Sofortmaßnahmen
  • 1. Perimeter-Inspektion: Relevante Portfreigaben und exponierte Endpunkte unverzüglich scannen.
  • 2. Patch-Applikation: Hersteller-Hotfix einspielen oder betroffene Daemons in isolierte DMZ-Segmente überführen.
  • 3. Telemetrie & EDR-Alerts: Prozessaufrufe und Child-Processes auf anomale Shell-Spawns überwachen.
🔗 Semantisch verwandte Zero-Days MariaDB 11.7 VEC
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten Urgent Security Alerts & Self-Hosted Swarm: Building Local LLM Infra Safely

Thematisch verwandte Begriffe: Urgent, Security, Alerts, SelfHosted · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-97179 | A security vulnerability has been detected in O2OA up to 9.5.3/10.0.2. T…
Advisory →
TTS Reader • tsecurity.de Voice
tsecurity.de Icon
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen

tsecurity.de Live Threat Radar

🔴 LIVE RADAR
MONITORING
AKTIV
CVE-DATENBANK
LIVE
🔍
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
🔖 Gespeicherte Artikel
📂 Keine gespeicherten Artikel vorhanden.
Zurück Ziehen Vor
Links: vorheriger Artikel Rechts: nächster Artikel unten: schließen
News NIS-2 Frühwarnung Tier-1 Intel TTP ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...

Zurück: vorheriger Vor: nächster
↗ Original-Quelle
Social Reaktionen Deine Reaktion zählt
Einstufung & Relevanz-Poll 0 Stimmen
In sozialen Netzwerken teilen 1-Klick