4 ms·
Terabytes of credentials leaked in supply-chain attack
- esseph 2mo ago> In all, both security firms said some 434,000 CI/CD (continuous integration/continuous delivery) software pipelines had credentials exposed after running the compromised LiteLLM versions. In many cases, researchers at CloudSEK and Hudson Rock had trouble identifying the organizations the credentials belonged to. For instance, an email address in the dump from the domain @siriusxm.com ultimately didn’t indicate a breach at the satellite broadcaster, but rather one within the infrastructure of SiriusXM subsidiary AdsWizz. Short List: Nvidia Corporation Amazon Web Services (AWS) Samsung Electronics samsung.com Salesforce, Inc. Cisco Systems, Inc. F. Hoffmann-La Roche AG ServiceNow Siemens AG S&P Global Airbus US Space & Defense John Deere Regeneron Pharmaceuticals, Inc. London Stock Exchange Group (LSEG) Thomson Reuters FedEx Munich Remunichre.com MediaTek Inc. Volkswagen AG Deloitte The Kroger Co. Siemens Energy Thales Group X Corp (Twitter) Zscaler, Inc. Epic Games Orange S.A. HP Inc. Philips Fortum Oyj Vodafone Group Plc Carl Zeiss AG Deutsche Bahn AG NGINX, Inc. BT Group Liebherr Krungthai Bank Public Company Limited Roku, Inc. Full List: https://exposure.cloudsek.com/ai-supply-chain-incident https://exposure.cloudsek.com/ai-supply-chain-incident
- esseph 2mo agoI'm not sure how this issue isn't on the front page, and I don't even care if this one were to be marked as a dupe or something but this is a MASSIVE breach. afaik the largest compromise ever?
- zahlman 2mo ago> In all, both security firms said some 434,000 CI/CD (continuous integration/continuous delivery) software pipelines had credentials exposed after running the compromised LiteLLM versions. So, averaging megabytes per pipeline. For username and password data. Really? We're talking about the credentials for the account responsible for the CI/CD processes in question, right? Not about end user data (since we're presumably talking about systems that haven't been deployed yet)?