PawsUp

1 readers
0 users here now
founded 2 months ago
ADMINS
701
702
703
704
705
706
707
 
 
708
 
 
709
710
711
712
713
714
715
 
 

Terabytes worth of credentials, many belonging to the world's biggest and most sensitive organizations, have been exposed in a supply-chain attack on LiteLLM, an open source tool that streamlines A- driven software development. Microsoft, Amazon, Cisco, Samsung, and Salesforce are only a handful of the entities whose access secrets were exposed.

The revelation was posted on Tuesday and Wednesday by security firms CloudSEK and Hudson Rock. CloudSEK said it found cloud keys, repository tokens, SSH keys, Kubernetes secrets, package publishing credentials, environment variables, and AlI provider keys that could allow attackers to gain access to more than 2,500 organizations.

The credentials were extracted during a 40-minute window in March while the victims used compromised versions of LiteLLM downloaded from the package’s official location in the Python Package Index repository. Hudson Rock said it made the discovery after analyzing a 195TB file that it obtained. Neither firm identified the source of the information.

716
 
 
717
718
 
 
719
 
 
720
 
 
721
 
 

Source (Bluesky)

722
723
724
725
321
Health (lemmy.world)
submitted 2 weeks ago* (last edited 2 weeks ago) by Return_of_Chippy@lemmy.world to c/memes@lemmy.world
 
 
view more: ‹ prev next ›