<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Segurança on Dudu | Tech &amp; Ideias</title><link>https://dudu.dev.br/tags/seguran%C3%A7a/</link><description>Recent content in Segurança on Dudu | Tech &amp; Ideias</description><generator>Hugo -- gohugo.io</generator><language>pt-br</language><copyright>© 2026 Carlos Eduardo de Alvarenga (Dudu)</copyright><lastBuildDate>Sun, 15 Mar 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://dudu.dev.br/tags/seguran%C3%A7a/index.xml" rel="self" type="application/rss+xml"/><item><title>Supply Chain Attack no LiteLLM: O Que Aprendemos</title><link>https://dudu.dev.br/posts/supply-chain-litellm/</link><pubDate>Sun, 15 Mar 2026 00:00:00 +0000</pubDate><guid>https://dudu.dev.br/posts/supply-chain-litellm/</guid><description>&lt;p>Este é um post de exemplo. Substitua pelo seu conteúdo.&lt;/p>
&lt;h2 class="relative group">O Ataque
&lt;div id="o-ataque" class="anchor">&lt;/div>
&lt;span
class="absolute top-0 w-6 transition-opacity opacity-0 ltr:-left-6 rtl:-right-6 not-prose group-hover:opacity-100">
&lt;a class="group-hover:text-primary-300 dark:group-hover:text-neutral-700"
style="text-decoration-line: none !important;" href="#o-ataque" aria-label="Âncora">#&lt;/a>
&lt;/span>
&lt;/h2>
&lt;p>Em 2025, o pacote LiteLLM no PyPI foi comprometido&amp;hellip;&lt;/p>
&lt;h2 class="relative group">Impacto
&lt;div id="impacto" class="anchor">&lt;/div>
&lt;span
class="absolute top-0 w-6 transition-opacity opacity-0 ltr:-left-6 rtl:-right-6 not-prose group-hover:opacity-100">
&lt;a class="group-hover:text-primary-300 dark:group-hover:text-neutral-700"
style="text-decoration-line: none !important;" href="#impacto" aria-label="Âncora">#&lt;/a>
&lt;/span>
&lt;/h2>
&lt;p>Para quem opera infraestrutura local de IA com LiteLLM como proxy&amp;hellip;&lt;/p>
&lt;h2 class="relative group">Lições
&lt;div id="li%C3%A7%C3%B5es" class="anchor">&lt;/div>
&lt;span
class="absolute top-0 w-6 transition-opacity opacity-0 ltr:-left-6 rtl:-right-6 not-prose group-hover:opacity-100">
&lt;a class="group-hover:text-primary-300 dark:group-hover:text-neutral-700"
style="text-decoration-line: none !important;" href="#li%C3%A7%C3%B5es" aria-label="Âncora">#&lt;/a>
&lt;/span>
&lt;/h2>
&lt;ol>
&lt;li>Fixe versões com hashes&lt;/li>
&lt;li>Use ambientes isolados&lt;/li>
&lt;li>Monitore dependências com ferramentas automatizadas&lt;/li>
&lt;/ol>
&lt;hr>
&lt;p>&lt;em>Este post faz parte da série &lt;a href="https://dudu.dev.br/series/ia-respons%c3%a1vel/">IA Responsável&lt;/a>.&lt;/em>&lt;/p></description></item></channel></rss>