Urgent.News

600+ sources. One page. See who else covered it.

Editions

Tech

Terabytes of credentials leaked in massive supply-chain attack

The data was scraped and exfiltrated from 2,500 users of a compromised AI package.

Terabytes of credentials leaked in massive supply-chain attack

In a massive supply-chain attack, terabytes of sensitive credentials have been exposed, affecting numerous prominent organizations including Microsoft, Amazon, Cisco, Samsung, and Salesforce. These credentials, which include cloud keys, repository tokens, SSH keys, Kubernetes secrets, package publishing credentials, environment variables, and AI provider keys, were extracted during a 40-minute window in March when victims used compromised versions of LiteLLM, an open-source AI-driven software development tool.

The breach was discovered by security firms CloudSEK and Hudson Rock, who analyzed a 195TB file obtained from the Python Package Index repository. The source of the information remains unidentified.

Brief written by urgent.news from Ars Technica's own syndicated text. Machine-written — may contain errors; check the original before relying on it.

Read the original at arstechnica.com →

More in Tech

Building a Graph From Tabular Relationship Data

Almost every graph starts life as relational tables. The conversion is mechanical once three decisions are made, and one of the three — id remapping — is a silent correctness bug rather than a matter…

MLB hires indie Mosaic app developer

MLB hires indie Mosaic app developer

The namesake Mosaic, now operated by MLB and on Apple TV. Formerly indie developer Jason Weingardt, on Threads: Some personal news: I’ve joined the team at Major League Baseball, and the Mosaic app…

More from Wednesday 12 August →