Massive Supply-Chain Breach Exposes Terabytes of Corporate Credentials

A supply-chain attack on LiteLLM, an open-source tool used to streamline AI software development, exposed terabytes of credentials belonging to major organizations including Microsoft, Amazon, Cisco, Samsung, and Salesforce. Security firms CloudSEK and Hudson Rock reported the breach, noting that cloud keys, repository tokens, SSH keys, Kubernetes secrets, and other sensitive data were harvested during a 40-minute window in March from compromised LiteLLM packages downloaded via the Python Package Index.

The stolen credentials could potentially allow attackers to access more than 2,500 organizations. Hudson Rock identified the exposure after analyzing a 195TB file, though the source of the leaked data has not been disclosed.

vidgetc Tech, gaming & AI news — always at hand Google Play · Soon App Store · Soon
💬 Discuss

Comments

Next articleDeepMind’s AI Model Gives Hurricane Forecasters an Extra Day of Warning
Start typing to search