The LiteLLM compromise is not in any of the places you would look for it
Both poisoned versions 404 on PyPI, no CVE was ever issued, and the KEV entry filed two days later belongs to the scanner rather than the gateway.
Read the source, then write down what it actually says
I build the evidence layer for AI agents, and I write about where it does not hold yet. Every figure below was read at its primary source, every note lists what it was checked against, and where a source did not support a claim the claim is not here.
Short, dated, and sourced. RSS
Both poisoned versions 404 on PyPI, no CVE was ever issued, and the KEV entry filed two days later belongs to the scanner rather than the gateway.
Coverage of the reasoning-trace harvest reported three different totals as if they disagreed. They are all the paper's own numbers, at three different denominators.
The gym booking story is being told as an API with no authorization. The agent's own account says two of the three operations it touched returned 403, and one did not.
Longer pieces, published on dev.to and cross-posted to Medium.
Three cases where a valid signature produced a false conclusion. Each one is a missing binding, not a missing signature.
Human block rates fall from about 17 percent to about 5 percent inside a single session. A control that decays the more you use it is not a control.
The best published number in agent security, ten months in production with zero false positives, still misses one attack in three.
Every party did their job correctly and the incident happened anyway, because no layer owned the question.
Stop prompt-engineering safety. Move the constraint off the probabilistic model and onto a deterministic knowledge graph.
We do not ask microservices nicely to respect rate limits. Safety is an architectural constraint, not a request.