Live data from Hacker News

Mercor says it was hit by cyberattack tied to compromise LiteLLM

techcrunch.com

61–62 of 62 posts

Re: Mercor says it was hit by cyberattack tied to compromise LiteLLM

#61
post #4

Earlier quoted context omitted.

[flagged]

What makes you think that? Your cab see the commit history ~10% of code is written by agents. Rest was all written by me. Unlike other criticisms of the project, this one feels personal as it is objectively incorrect.

Oops, sorry. Only had a look at recent commits.

Re: Mercor says it was hit by cyberattack tied to compromise LiteLLM

#62

Second major supply chain compromise in a week after the axios npm attack. 40 minutes and 500k machines affected. SOC2 won't catch this. The real question is whether your CI pipeline would have flagged a dependency change that happened between your last build and the one going to prod. Most teams have no visibility into that window at all.

> SOC2 won't catch this Cybersecurity professionals and their certification treadmill crack me up because of this They get paid less, require more certifications to be marketable, all to simply show actual “computer wizards” where all the blind spots are

I am not disagreeing with your main point, but want to clarify that SOC2 is not an individual certification that a person achieves.
Post reply on HN