Security Now (Audio) · TWiT

LiteLLM - Click Fix Attacks Surge

April 1, 2026·2 hr 49 min·5 clips
Steve Gibson reveals the LightLLM PyPI exploit, a supply chain attack that nearly infected millions of downloads.
The setup is deliberately cool-headed. Steve Gibson joins Leo for a security briefing built around LiteLLM, framed early as a PyPI problem pointed straight at coders. The banter is familiar. Leo is back from RSAC in San Francisco and briefly ties the week to Marcus Hutchins and the old WannaCry story. Then the list starts moving. The show works through age verification on Linux, Apple's response to the click-fix vulnerability, quantum computing worries, and the main LiteLLM thread. The best story is nearly absurd. Russian intelligence appears to have put spying hardware inside a thermostat meant for a Ukrainian drone factory, complete with a camera, microphone, and small router. Then the bit gets serious. Tech X already knew about the device because Ukrainian intelligence had warned them, so they installed it anyway and used it to send back a steady stream of deliberate disinformation. That is the useful security lesson here. A channel the attacker thought was unusually trustworthy became more useful to the defender because the attacker trusted it too much. Quantum risk gets the slower technical treatment. Gibson revisits earlier doubts about quantum factorization claims, especially examples built around artificial targets rather than practical attacks on RSA-style public key crypto. Google changes the mood a little. Its move to put Q-day planning at 2029 is treated less like a reason to panic and more like a reason to take migration seriously. The tone stays dry. Even with espionage, broken trust, and quantum deadlines on the table, the conversation keeps its usual order: mechanism first, alarm second. Click-fix fits that pattern too. Apple's move is described plainly as a useful response to the vulnerability. LiteLLM carries the coder warning. A PyPI exploit is not presented as exotic drama. It is the kind of ordinary failure that can walk right into a developer workflow. The episode does not offer much comfort. Its quieter point is that security failures often start where convenience, trust, and automation stop feeling suspicious.

As heard by us

A sharp Security Now episode on LiteLLM, click-fix attacks, quantum risk, and the strange theater of wartime surveillance.

Security Now builds this episode around LiteLLM, framed as a PyPI nightmare for coders, then widens out to click-fix attacks, Apple's response, Linux age verification, and Google's newly aggressive 2029 quantum warning.

Read the full review in PlayNext →

Why you'd press play

Malicious code slipped into a popular AI Python package, and this episode breaks down exactly how it happened.

Read the full recommendation in PlayNext →
Listen to the show on