×
Mercor says it was hit by cyberattack tied to compromise of open-source LiteLLM project | TechCrunch

Mercor says it was hit by cyberattack tied to compromise of open-source LiteLLM project | TechCrunch

Mercor, a popular AI recruiting startup, has confirmed a security incident linked to a supply chain attack involving the open-source project LiteLLM.

The AI startup told TechCrunch on Tuesday that it was “one of thousands of companies” affected by a recent compromise of LiteLLM’s project, which was linked to a hacking group called TeamPCP. Confirmation of the incident comes as extortion hacking group Lapsus$ claimed it had targeted Mercor and gained access to its data.

It’s not immediately clear how the Lapsus$ gang obtained the stolen data from Mercor as part of TeamPCP’s cyberattack.

Founded in 2023, Mercor works with companies including OpenAI and Anthropic to train AI models by contracting specialized domain experts such as scientists, doctors, and lawyers from markets including India. The startup says it facilitates more than $2 million in daily payouts and was valued at $10 billion following a $350 million Series C round led by Felicis Ventures in October 2025.

Mercor spokesperson Heidi Hagberg confirmed to TechCrunch that the company had “moved promptly” to contain and remediate the security incident.

“We are conducting a thorough investigation supported by leading third-party forensics experts,” said Hagberg. “We will continue to communicate with our customers and contractors directly as appropriate and devote the resources necessary to resolving the matter as soon as possible.”

Earlier, Lapsus$ claimed responsibility for the apparent data breach on its leak site and shared a sample of data allegedly taken from Mercor, which TechCrunch reviewed. The sample included material referencing Slack data and what appeared to be ticketing data, as well as two videos purportedly showing conversations between Mercor’s AI systems and contractors on its platform.

Techcrunch event

San Francisco, CA
|
October 13-15, 2026

Hagberg declined to answer follow-up questions on whether the incident was connected to claims by Lapsus$, or whether any customer or contractor data had been accessed, exfiltrated, or misused.

The compromise of LiteLLM originally surfaced last week after malicious code was discovered in a package associated with the Y Combinator-backed startup’s open-source project. While the malicious code was identified and removed within hours, the incident drew scrutiny due to LiteLLM’s widespread use around the internet, with the library downloaded millions of times per day, per security firm Snyk. The incident also prompted LiteLLM to make changes to its compliance processes, including shifting from controversial startup Delve to Vanta for compliance certifications.

It remains unclear how many companies were affected by the LiteLLM-related incident or whether any data exposure occurred, as investigations continue.

Source link
#Mercor #hit #cyberattack #tied #compromise #opensource #LiteLLM #project #TechCrunch

OpenAI is launching Daybreak, an AI initiative focused on detecting and patching vulnerabilities before attackers find them. Daybreak uses the Codex Security AI agent that launched in March to create a threat model based on an organization’s code and focus on possible attack paths, validate likely vulnerabilities, and then automate the detection of the higher risk ones.

Its launch comes just over a month after rival Anthropic announced Claude Mythos, a security-focused AI model it claimed was too dangerous to publicly release and only shared privately as a part of its own initiative, dubbed Project Glasswing. Still, that didn’t stop at least a few unauthorized parties from getting access.

However, OpenAI has so far lacked a similar security product. Like Glasswing, Daybreak isn’t built on just one AI model — OpenAI says “Daybreak brings together the most capable OpenAI models, Codex, and our security partners.”

Daybreak also involves specialized cyber models, including GPT-5.5 with Trusted Access for Cyber and GPT-5.5-Cyber, which began rolling out last week. OpenAI also says it’s working with its “industry and government partners” while it prepares to “deploy increasingly more cyber-capable models.”

#OpenAI #released #answer #Claude #MythosAI,Anthropic,News,OpenAI,Security,Tech">OpenAI just released its answer to Claude MythosOpenAI is launching Daybreak, an AI initiative focused on detecting and patching vulnerabilities before attackers find them. Daybreak uses the Codex Security AI agent that launched in March to create a threat model based on an organization’s code and focus on possible attack paths, validate likely vulnerabilities, and then automate the detection of the higher risk ones.Its launch comes just over a month after rival Anthropic announced Claude Mythos, a security-focused AI model it claimed was too dangerous to publicly release and only shared privately as a part of its own initiative, dubbed Project Glasswing. Still, that didn’t stop at least a few unauthorized parties from getting access.However, OpenAI has so far lacked a similar security product. Like Glasswing, Daybreak isn’t built on just one AI model — OpenAI says “Daybreak brings together the most capable OpenAI models, Codex, and our security partners.”Daybreak also involves specialized cyber models, including GPT-5.5 with Trusted Access for Cyber and GPT-5.5-Cyber, which began rolling out last week. OpenAI also says it’s working with its “industry and government partners” while it prepares to “deploy increasingly more cyber-capable models.”#OpenAI #released #answer #Claude #MythosAI,Anthropic,News,OpenAI,Security,Tech

Daybreak, an AI initiative focused on detecting and patching vulnerabilities before attackers find them. Daybreak uses the Codex Security AI agent that launched in March to create a threat model based on an organization’s code and focus on possible attack paths, validate likely vulnerabilities, and then automate the detection of the higher risk ones.

Its launch comes just over a month after rival Anthropic announced Claude Mythos, a security-focused AI model it claimed was too dangerous to publicly release and only shared privately as a part of its own initiative, dubbed Project Glasswing. Still, that didn’t stop at least a few unauthorized parties from getting access.

However, OpenAI has so far lacked a similar security product. Like Glasswing, Daybreak isn’t built on just one AI model — OpenAI says “Daybreak brings together the most capable OpenAI models, Codex, and our security partners.”

Daybreak also involves specialized cyber models, including GPT-5.5 with Trusted Access for Cyber and GPT-5.5-Cyber, which began rolling out last week. OpenAI also says it’s working with its “industry and government partners” while it prepares to “deploy increasingly more cyber-capable models.”

#OpenAI #released #answer #Claude #MythosAI,Anthropic,News,OpenAI,Security,Tech">OpenAI just released its answer to Claude Mythos

OpenAI is launching Daybreak, an AI initiative focused on detecting and patching vulnerabilities before attackers find them. Daybreak uses the Codex Security AI agent that launched in March to create a threat model based on an organization’s code and focus on possible attack paths, validate likely vulnerabilities, and then automate the detection of the higher risk ones.

Its launch comes just over a month after rival Anthropic announced Claude Mythos, a security-focused AI model it claimed was too dangerous to publicly release and only shared privately as a part of its own initiative, dubbed Project Glasswing. Still, that didn’t stop at least a few unauthorized parties from getting access.

However, OpenAI has so far lacked a similar security product. Like Glasswing, Daybreak isn’t built on just one AI model — OpenAI says “Daybreak brings together the most capable OpenAI models, Codex, and our security partners.”

Daybreak also involves specialized cyber models, including GPT-5.5 with Trusted Access for Cyber and GPT-5.5-Cyber, which began rolling out last week. OpenAI also says it’s working with its “industry and government partners” while it prepares to “deploy increasingly more cyber-capable models.”

#OpenAI #released #answer #Claude #MythosAI,Anthropic,News,OpenAI,Security,Tech
Five-year-old European military drone startup Helsing is reportedly close to raising a new $1.2 billion round at about an $18 billion valuation. The round is expected to be led by Dragoneer and co-led by existing Helsing investor Lightspeed, the Financial Times reported.

Helsing last raised just under a year ago, in June 2025, in a deal that was led by billionaire Spotify founder Daniel Ek. That was a €600 million investment at an estimated €12 billion valuation ($14 billion USD). So this new round is a step-up.

While Helsing isn’t the only European unicorn defense tech, it is by far the one that investors deem the most valuable. For instance, German drone maker Quantum Systems raised €180 million in November, which valued it at more than €3 billion. And a year ago, Lisbon-headquartered Tekever raised £400 million at a valuation above £1 billion. Amid Russia’s ongoing war in Ukraine, the proving ground for new technologies, autonomous defense startups have become a hot area for VCs.

Helsing, Dragoneer, and Lightspeed could not be immediately reached for comment.

#Daniel #Ekbacked #defense #tech #Helsing #raise #1.2B #18B #valuation #TechCrunchdrones,Fundraise,helsing">Daniel Ek-backed defense tech Helsing to raise .2B at B valuation | TechCrunch
Five-year-old European military drone startup Helsing is reportedly close to raising a new .2 billion round at about an  billion valuation. The round is expected to be led by Dragoneer and co-led by existing Helsing investor Lightspeed, the Financial Times reported.

Helsing last raised just under a year ago, in June 2025, in a deal that was led by billionaire Spotify founder Daniel Ek. That was a €600 million investment at an estimated €12 billion valuation ( billion USD). So this new round is a step-up.







While Helsing isn’t the only European unicorn defense tech, it is by far the one that investors deem the most valuable. For instance, German drone maker Quantum Systems raised €180 million in November, which valued it at more than €3 billion. And a year ago, Lisbon-headquartered Tekever raised £400 million at a valuation above £1 billion. Amid Russia’s ongoing war in Ukraine, the proving ground for new technologies, autonomous defense startups have become a hot area for VCs.

Helsing, Dragoneer, and Lightspeed could not be immediately reached for comment.


#Daniel #Ekbacked #defense #tech #Helsing #raise #1.2B #18B #valuation #TechCrunchdrones,Fundraise,helsing

Helsing is reportedly close to raising a new $1.2 billion round at about an $18 billion valuation. The round is expected to be led by Dragoneer and co-led by existing Helsing investor Lightspeed, the Financial Times reported.

Helsing last raised just under a year ago, in June 2025, in a deal that was led by billionaire Spotify founder Daniel Ek. That was a €600 million investment at an estimated €12 billion valuation ($14 billion USD). So this new round is a step-up.

While Helsing isn’t the only European unicorn defense tech, it is by far the one that investors deem the most valuable. For instance, German drone maker Quantum Systems raised €180 million in November, which valued it at more than €3 billion. And a year ago, Lisbon-headquartered Tekever raised £400 million at a valuation above £1 billion. Amid Russia’s ongoing war in Ukraine, the proving ground for new technologies, autonomous defense startups have become a hot area for VCs.

Helsing, Dragoneer, and Lightspeed could not be immediately reached for comment.

#Daniel #Ekbacked #defense #tech #Helsing #raise #1.2B #18B #valuation #TechCrunchdrones,Fundraise,helsing">Daniel Ek-backed defense tech Helsing to raise $1.2B at $18B valuation | TechCrunch

Five-year-old European military drone startup Helsing is reportedly close to raising a new $1.2 billion round at about an $18 billion valuation. The round is expected to be led by Dragoneer and co-led by existing Helsing investor Lightspeed, the Financial Times reported.

Helsing last raised just under a year ago, in June 2025, in a deal that was led by billionaire Spotify founder Daniel Ek. That was a €600 million investment at an estimated €12 billion valuation ($14 billion USD). So this new round is a step-up.

While Helsing isn’t the only European unicorn defense tech, it is by far the one that investors deem the most valuable. For instance, German drone maker Quantum Systems raised €180 million in November, which valued it at more than €3 billion. And a year ago, Lisbon-headquartered Tekever raised £400 million at a valuation above £1 billion. Amid Russia’s ongoing war in Ukraine, the proving ground for new technologies, autonomous defense startups have become a hot area for VCs.

Helsing, Dragoneer, and Lightspeed could not be immediately reached for comment.

#Daniel #Ekbacked #defense #tech #Helsing #raise #1.2B #18B #valuation #TechCrunchdrones,Fundraise,helsing

Post Comment