News · curated 16 Jul 2026
Anthropic Leak & Mercor Attack | Enterprise AI Security Risks | Proofpoint US
First reported proofpoint.com
Coverage timeline
Single-source analysis — first reported, latest, and curated coincide.
Why it matters
The Mercor incident shows that AI supply chains built on shared open-source libraries like LiteLLM can be weaponized to harvest API keys and exfiltrate data, making dependency and non-human-identity governance a defensive priority.
Proofpoint reports two April 2026 AI security incidents: an Anthropic leak that exposed internal files and Claude Code source code via a release packaging error, and a Mercor supply-chain attack in which malicious code embedded in the open-source LiteLLM library (used to connect applications to AI services) stole API keys and customer data, attributed to Team PCP within the Lapsus$ group. The piece frames these as evidence that AI security failures are operational and governance failures involving human error, insecure integrations, and compromised dependencies.