加载中... --°C -- · --% · --
|
加载中... --°C -- · --% · --

Terabytes of credentials leaked in massive supply-chain attack

AI工具 杂七杂八
Terabytes of credentials leaked in massive supply-chain attack
摘要

安全厂商CloudSEK与Hudson Rock披露,开源AI开发工具LiteLLM遭遇供应链攻击,导致数TB规模的凭据泄露,涉及微软、亚马逊、思科、三星、Salesforce等众多大型及敏感机构。攻击者利用从Python包索引官方位置下载的受损LiteLLM版本,在3月一个40分钟的时间窗口内窃取了云密钥、仓库令牌、SSH密钥、Kubernetes密钥及A

Terabytes worth of credentials, many belonging to the world’s biggest and most sensitive organizations, have been exposed in a supply-chain attack on LiteLLM, an open source tool that streamlines AI-driven software development. Microsoft, Amazon, Cisco, Samsung, and Salesforce are only a handful of the entities whose access secrets were exposed.

The revelation was posted on Tuesday and Wednesday by security firms CloudSEK and Hudson Rock. CloudSEK said it found cloud keys, repository tokens, SSH keys, Kubernetes secrets, package publishing credentials, environment variables, and AI provider keys that could allow attackers to gain access to more than 2,500 organizations.

40 minutes is all it takes

The credentials were extracted during a 40-minute window in March while the victims used compromised versions of LiteLLM downloaded from the package’s official location in the Python Package Index repository. Hudson Rock said it made the discovery after analyzing a 195TB file that it obtained. Neither firm identified the source of the information.

Read full article

Comments

转载信息
原文: Terabytes of credentials leaked in massive supply-chain attack (2026-08-12T21:43:21)
作者: Dan Goodin 分类: 科技
评论 (0)
登录 后发表评论

暂无评论,来留下第一条评论吧