Live data from Hacker News

Mercor says it was hit by cyberattack tied to compromise LiteLLM

techcrunch.com

51–60 of 62 posts

Re: Mercor says it was hit by cyberattack tied to compromise LiteLLM

#52
post #21
post #7

> The incident also prompted LiteLLM to make changes to its compliance processes, including shifting from controversial startup Delve to Vanta for compliance certifications. This is pretty funny. The leaked excel sheet with customers of Delve is basically a shortlist of targets for hackers to try now. Not that they necessarily have bad security, but you can play the odds

I am not defending Delve or anything and I hope they get what they deserver but there is no correlation between SOC2 certification and the actual cyber capability of a company. SOC2 and ISO27001 is just compliance and frankly most of it is BS.

According to SemiAnalysis, it is akin to getting a FAA certification.

https://x.com/HotAisle/status/2035062702587232458

Re: Mercor says it was hit by cyberattack tied to compromise LiteLLM

#55

Could not happened to a more usurious company.

LinkedIn itself is far from great, but this seems like a good thread to share my LinkedIn tip of creating a job alert using a search query like

rust embedded NOT lensa NOT jobot NOT alignerr NOT mercor NOT “crossing hurdles”

Re: Mercor says it was hit by cyberattack tied to compromise LiteLLM

#56

Second major supply chain compromise in a week after the axios npm attack. 40 minutes and 500k machines affected. SOC2 won't catch this. The real question is whether your CI pipeline would have flagged a dependency change that happened between your last build and the one going to prod. Most teams have no visibility into that window at all.

> SOC2 won't catch this

Cybersecurity professionals and their certification treadmill crack me up because of this

They get paid less, require more certifications to be marketable, all to simply show actual “computer wizards” where all the blind spots are

Re: Mercor says it was hit by cyberattack tied to compromise LiteLLM

#57

Second major supply chain compromise in a week after the axios npm attack. 40 minutes and 500k machines affected. SOC2 won't catch this. The real question is whether your CI pipeline would have flagged a dependency change that happened between your last build and the one going to prod. Most teams have no visibility into that window at all.

[dead]

Re: Mercor says it was hit by cyberattack tied to compromise LiteLLM

#60
post #21

Earlier quoted context omitted.

I am not defending Delve or anything and I hope they get what they deserver but there is no correlation between SOC2 certification and the actual cyber capability of a company. SOC2 and ISO27001 is just compliance and frankly most of it is BS.

I went through SOC2 Type I and II. I’d say that most of that stuff is necessary , like splitting environments and so on. That doesn’t mean it’s anything close to sufficient to avoid being hacked. It’s a framework to give you the direction, then if employees are careless (or even malicious), no security standard is complete enough to protect a company.

Not to be pedantic about the topic but SOC 2 is an auditing standard, not a security framework. It defines what you’ll be assessed against but it doesn’t tell you how to build your security program. You’ll find the prescriptive controls in real frameworks like ISO 27001, NIST CSF, or CIS Controls which do give you a structure for implementing security.
Post reply on HN