Close Menu
AI News TodayAI News Today

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    As AI safety concerns mount, three pioneers make the case for staying open

    DeepSeek V4 Pro 0813 (on OpenRouter)

    Have physicists finally discovered glueballs? New evidence points to yes.

    Facebook X (Twitter) Instagram
    • About Us
    • Contact Us
    Facebook X (Twitter) Instagram Pinterest Vimeo
    AI News TodayAI News Today
    • Home
    • AI News
    • AI Reviews
    • AI Tools
    • AI Tutorials
    • Chatbots
    • Free AI Tools
    • Artificial Intelligence
    AI News TodayAI News Today
    Home»AI Reviews»Terabytes of credentials leaked in massive supply-chain attack
    AI Reviews

    Terabytes of credentials leaked in massive supply-chain attack

    By No Comments2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    A cartoon man runs across a white field of ones and zeroes.
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The firm advised all those affected to perform “aggressive credential revocation,” assume any secret accessible to the LiteLLM environment is compromised, invalidate and rotate all cloud keys, Kubernetes service account tokens, and GitLab/GitHub PATs, and audit logging and egress filtering.

    As a cautionary tale, CloudSEK said that Trivy developers rotated, but failed to fully revoke an automation token over a 20-day window. The lapse gave the attackers a nearly three-week period to force-push malicious code to third-party builds that used the vulnerability scanner. As Beaumont observed, organizations’ rush to integrate AI into their software delivery systems has also greatly contributed to the scale of the damage.

    Update:There are already signs that some of the affected organizations aren’t taking the disclosure with the seriousness warranted. After this post went live, Beaumont reported:

    These creds date from about March. One of the orgs impacted told me they’d rotated them all and it’s a nothingburger, so I looked at their responsible disclosure policy, it allows trying creds, so I tried them all. Almost every one worked. Submitted report. One of the biggest US techcos.

    Ultimately, the new revelations concerning the LiteLLM supply-chain attack underscore the growing threat of such campaigns and hence the importance of maintaining vigilance around the use of open source software that, when infected, can spread rapidly across the Internet.

    “The key takeaway is how supply chains have evolved to make a single upstream breach affect thousands of companies simultaneously,” Alon Gal, co-founder and chief technology officer of Hudson Rock, wrote in an email. “A window of roughly 40 minutes in which the LiteLLM dependency was hacked led to over 430,000 instances in which millions of secrets were harvested. This magnitude pushes us into a completely new world regarding the type of response required from the cybersecurity industry.”

    Post updated to add image.

    attack credentials leaked Massive SupplyChain Terabytes
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleAI nuclear power firm Fermi finally has a new CEO
    Next Article This 8BitDo mechanical keyboard has an extra keypad and is 30 percent off
    • Website

    Related Posts

    AI Reviews

    As AI safety concerns mount, three pioneers make the case for staying open

    AI Reviews

    Apple Faces Lawsuit Over iCloud Private Relay Vulnerability

    AI Reviews

    Pixel 11 event live blog: Let’s watch Trevor Noah introduce Google’s new phones

    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    As AI safety concerns mount, three pioneers make the case for staying open

    0 Views

    DeepSeek V4 Pro 0813 (on OpenRouter)

    0 Views

    Have physicists finally discovered glueballs? New evidence points to yes.

    0 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    AI Tutorials

    Quantization from the ground up

    AI Tools

    David Sacks is done as AI czar — here’s what he’s doing instead

    AI Reviews

    Judge sides with Anthropic to temporarily block the Pentagon’s ban

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    As AI safety concerns mount, three pioneers make the case for staying open

    0 Views

    DeepSeek V4 Pro 0813 (on OpenRouter)

    0 Views

    Have physicists finally discovered glueballs? New evidence points to yes.

    0 Views
    Our Picks

    Quantization from the ground up

    David Sacks is done as AI czar — here’s what he’s doing instead

    Judge sides with Anthropic to temporarily block the Pentagon’s ban

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Terms & Conditions
    • Privacy Policy
    • Disclaimer

    © 2026 ainewstoday.co. All rights reserved. Designed by DD.

    Type above and press Enter to search. Press Esc to cancel.