Bg Shape
Image

VMware vCentre Backdoor, LiteLLM Supply Chain Attack & Azure Entra ID Targeted

Robert Kehoe
Chief Technology Officer
Published:
August 21, 2026

Three stories this week that cut across infrastructure, developer tooling and identity security: a China-backed APT using ransomware as cover for a backdoor operation, a poisoned dependency cascading through thousands of build pipelines, and a ransomware group harvesting Azure credentials to fuel phishing campaigns.

VMware vCentre | Ransomware Was the Smokescreen

A China-backed APT has been actively exploiting a critical vulnerability in VMware vCentre, scoring 9.8 on the CVSS scale. The vulnerability allows directory traversal and privilege escalation, giving attackers significant reach once inside.

What makes this attack unusual is the sequence. The group installed a persistent backdoor first, and only then deployed ransomware. That is not typical ransomware behaviour. It strongly suggests the primary objective was data collection, with the ransomware deployed as a distraction to obscure the real intent and complicate forensic investigation.

What to do:
Patch vCentre to the latest version immediately if you have not already done so. More importantly, do not assume patching closes the issue. If this APT was active in your environment before you patched, a backdoor may already be present. Review logs for signs of lateral movement or unusual outbound connections and investigate before declaring the all clear.

LiteLLM Supply Chain Attack Hits 2,500 Build Pipelines

A threat actor identified as Team PCP poisoned a Trivy dependency within LiteLLM, triggering a cascading supply chain attack that reached over 2,500 organisation build pipelines. CI/CD pipelines are high-value targets precisely because they carry privileged access to a large number of downstream systems, and they are frequently under-monitored relative to that access level.

This is another example of the risk posed by implicit trust in third-party dependencies. One compromised package, deployed quietly, can propagate through an entire software delivery chain before anyone notices.

What to do:
Update LiteLLM and Trivy to the latest versions immediately. Rotate all pipeline secrets currently in use. Pin versions across all dependencies so that future updates require a deliberate action rather than happening automatically. Treat your CI/CD pipeline with the same security rigour you apply to production systems, because the access it holds warrants it.

Azure Entra ID Targeted Using Stolen Credentials

A ransomware group has been targeting Azure Active Directory and Entra ID using stolen credentials to log in and exfiltrate user data at scale. The data being taken includes names, email addresses and physical addresses, the kind of information that on its own looks low value but in practice becomes the raw material for highly convincing phishing campaigns.

The risk here is downstream. An attacker who knows the names of your colleagues, your boss and your suppliers can craft emails that are difficult to distinguish from legitimate internal communication. The kind that reference a conversation that apparently happened yesterday, or ask you to authorise an invoice on behalf of someone you know.

What to do:
Enable MFA on every Azure and Entra ID account in your organisation. Administrator accounts in particular should have MFA enforced without exceptions. Stolen credentials alone should not be enough to access your environment.

Read Our Latest Blogs

Blog Image
VMware vCentre Backdoor, LiteLLM Supply Chain Attack & Azure Entra ID Targeted

China-backed APT exploits VMware vCentre, LiteLLM supply chain attack hits 2,500 pipelines, and Azure Entra ID targeted with stolen credentials.

Blog Image
Bringing OT Under Your SOC: Lessons from Real-World Attacks

US water utility hacks and a Polish CHP plant breach expose OT security's real gaps. A practical five-stage plan to bring OT under SOC monitoring.

Blog Image
JFrog Confirmed AI Attack, Minnesota Water Attack & Coca-Cola Refuse to Pay

JFrog patches the zero-day used in the Hugging Face breach, Coca-Cola's Fairlife hit by Anubis ransomware, and a coordinated attack knocks out Minnesota water systems.

Bg ShapeBg Shape
BLOGS & INSIGHTS

VMware vCentre Backdoor, LiteLLM Supply Chain Attack & Azure Entra ID Targeted

Threat Actors and Campaigns
Supply Chain and Third Party Risks
Phishing and Social Engineering
Robert Kehoe
Chief Technology Officer
August 21, 2026

Three stories this week that cut across infrastructure, developer tooling and identity security: a China-backed APT using ransomware as cover for a backdoor operation, a poisoned dependency cascading through thousands of build pipelines, and a ransomware group harvesting Azure credentials to fuel phishing campaigns.

VMware vCentre | Ransomware Was the Smokescreen

A China-backed APT has been actively exploiting a critical vulnerability in VMware vCentre, scoring 9.8 on the CVSS scale. The vulnerability allows directory traversal and privilege escalation, giving attackers significant reach once inside.

What makes this attack unusual is the sequence. The group installed a persistent backdoor first, and only then deployed ransomware. That is not typical ransomware behaviour. It strongly suggests the primary objective was data collection, with the ransomware deployed as a distraction to obscure the real intent and complicate forensic investigation.

What to do:
Patch vCentre to the latest version immediately if you have not already done so. More importantly, do not assume patching closes the issue. If this APT was active in your environment before you patched, a backdoor may already be present. Review logs for signs of lateral movement or unusual outbound connections and investigate before declaring the all clear.

LiteLLM Supply Chain Attack Hits 2,500 Build Pipelines

A threat actor identified as Team PCP poisoned a Trivy dependency within LiteLLM, triggering a cascading supply chain attack that reached over 2,500 organisation build pipelines. CI/CD pipelines are high-value targets precisely because they carry privileged access to a large number of downstream systems, and they are frequently under-monitored relative to that access level.

This is another example of the risk posed by implicit trust in third-party dependencies. One compromised package, deployed quietly, can propagate through an entire software delivery chain before anyone notices.

What to do:
Update LiteLLM and Trivy to the latest versions immediately. Rotate all pipeline secrets currently in use. Pin versions across all dependencies so that future updates require a deliberate action rather than happening automatically. Treat your CI/CD pipeline with the same security rigour you apply to production systems, because the access it holds warrants it.

Azure Entra ID Targeted Using Stolen Credentials

A ransomware group has been targeting Azure Active Directory and Entra ID using stolen credentials to log in and exfiltrate user data at scale. The data being taken includes names, email addresses and physical addresses, the kind of information that on its own looks low value but in practice becomes the raw material for highly convincing phishing campaigns.

The risk here is downstream. An attacker who knows the names of your colleagues, your boss and your suppliers can craft emails that are difficult to distinguish from legitimate internal communication. The kind that reference a conversation that apparently happened yesterday, or ask you to authorise an invoice on behalf of someone you know.

What to do:
Enable MFA on every Azure and Entra ID account in your organisation. Administrator accounts in particular should have MFA enforced without exceptions. Stolen credentials alone should not be enough to access your environment.

Robert Kehoe

Chief Technology Officer

Robert is CTO at Smarttech247, leading engineering strategy and delivery across cybersecurity products and services. With over 15 years’ experience in software and security, and CISSP certified, he has led large-scale cloud and security initiatives, including Cloud Protection for Salesforce. Robert focuses on measurable customer outcomes and building empowered, high-performing engineering teams.

Contents:

Ready to scale your security and compliance operations?

We protect your on-premise/cloud/OT environments - 24x7x365