{
  "id": 703644,
  "title": "Terabytes of credentials leaked in massive supply-chain attack",
  "url": "https://urgent.news/2026/08/12/terabytes-of-credentials-leaked-in-massive-supply-chain-attack",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-12T21:43:21.000Z",
  "source": {
    "name": "Ars Technica",
    "slug": "ars-technica",
    "url": "https://arstechnica.com/security/2026/08/terabytes-of-credentials-leaked-in-massive-supply-chain-attack/"
  },
  "original_language": "en",
  "account": null,
  "summary": "In a massive supply-chain attack, terabytes of sensitive credentials have been exposed, affecting numerous prominent organizations including Microsoft, Amazon, Cisco, Samsung, and Salesforce. These credentials, which include cloud keys, repository tokens, SSH keys, Kubernetes secrets, package publishing credentials, environment variables, and AI provider keys, were extracted during a 40-minute window in March when victims used compromised versions of LiteLLM, an open-source AI-driven software development tool. The breach was discovered by security firms CloudSEK and Hudson Rock, who analyzed a 195TB file obtained from the Python Package Index repository. The source of the information remains unidentified.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}