Fernando Tucci
6 articles
-
BlogYour AI Gateway Was a Backdoor: Inside the LiteLLM Supply Chain Compromise
TeamPCP orchestrated one of the most sophisticated multi-ecosystem supply chain campaigns publicly documented to date. It cascaded through developer tooling and compromised LiteLLM and exposed how AI proxy services that concentrate API keys and cloud credentials become high-value collateral when supply chain attacks compromise upstream dependencies.
March 26th, 2026 26 minPeter Girnus, Deep Patel, Simon Dulude, Ashish Verma…
Read article -
BlogYour AI Stack Just Handed Over Your Root Keys: Inside the litellm PyPI Breach
Litellm PyPI breach explained: malicious versions steal cloud credentials, SSH keys, and Kubernetes secrets. Learn impact and urgent mitigation steps.
March 25th, 2026 6 minFernando Tucci
Read article -
BlogCISOs in a Pinch: A Security Analysis of OpenClaw
Learn about OpenClaw (a sovereign agent) and how this can be viable for enterprises.
March 10th, 2026 5 minFernando Tucci
Read article -
BlogViral AI, Invisible Risks: What OpenClaw Reveals About Agentic Assistants
OpenClaw (aka Clawdbot or Moltbot) represents a new frontier in agentic AI: powerful, highly autonomous, and surprisingly easy to use. In this research, we examine how its capabilities compare to its predecessors’ and highlight the security risks inherent to the agentic AI paradigm.
February 6th, 2026 14 minSalvatore Gariuolo, Vincenzo Ciancaglini, Fernando Tucci
Read article -
ResearchStay Ahead of AI Threats: Secure LLM Applications With Trend Vision One
Trend Vision One™ tackles 9 of OWASP’s Top 10 LLM vulnerabilities, offering comprehensive protection against prompt injection, data leakage, AI supply chain risks, and other critical flaws.
October 14th, 2025 4 minFernando Cardoso, Dave McDuff, Fernando Tucci, Kim Kinahan…
Read article -
ResearchThe Road to Agentic AI: Navigating Architecture, Threats, and Solutions
As agentic AI systems grow increasingly complex, it becomes clear that this class of applications relies on a multi-layered architecture. Trying to chart such architecture reveals several security risks that could plague each layer. This article investigates the possible scenarios and offers actionable insights to secure each layer and combat such threats.
July 28th, 2025Fernando Tucci, Vincenzo Ciancaglini, Marco Balduzzi, Salvatore Gariuolo…
Read article