<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Llm-Supply-Chain on CuraSec</title><link>https://curasec.metacog.co.kr/tags/llm-supply-chain/</link><description>Recent content in Llm-Supply-Chain on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 24 Aug 2026 13:10:29 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/llm-supply-chain/index.xml" rel="self" type="application/rss+xml"/><item><title>Prefix-Cache Side Channel Exposes Hidden LLM API Reseller Dependencies</title><link>https://curasec.metacog.co.kr/insights/2026-08-24-uncovering-and-understanding-hidden-dependencies-in-the-llm/</link><pubDate>Mon, 24 Aug 2026 13:10:29 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-24-uncovering-and-understanding-hidden-dependencies-in-the-llm/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> CacheTracer demonstrates that LLM API reseller chains are often multi-layer and opaque — prompts may traverse undisclosed intermediaries who can inspect or alter them. No patch exists; the takeaway is to audit which LLM API endpoints you use and prefer direct provider access or contractually disclosed routing for sensitive workloads.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> This research surfaces a concrete vendor-risk gap: LLM API resellers may introduce undisclosed intermediaries with access to prompt and response content, creating confidentiality exposure. Add LLM API supply chain transparency (direct vs. reseller routing, data-handling attestations) to your AI vendor risk review criteria this quarter.&lt;/li>
&lt;/ul></description></item></channel></rss>