Terabytes of credentials leaked in massive supply-chain attack
Summary
A cyberattack exposed terabytes of sensitive login details from over 2,500 organizations by targeting LiteLLM, an open source tool used for AI software development. The breach happened during a 40-minute window in March when users downloaded compromised versions of LiteLLM from an official software repository.Key Facts
- The leaked data included cloud keys, tokens, passwords, and other credentials that could let attackers access company systems.
- Companies affected include Microsoft, Amazon, Cisco, Samsung, Salesforce, Nvidia, and many others.
- The attack was a supply-chain type, meaning the hacker gained access via trusted software used by many organizations.
- The compromised LiteLLM versions accessed computer memory to steal data and sent it to the attackers.
- A hacker group called TeamPCP, mostly teenagers, claimed responsibility for the breach.
- Other affected software includes the vulnerability scanner Trivy, KICS, and the Telnyx Python SDK.
- Approximately 434,000 software pipelines for building and deploying software (CI/CD pipelines) were exposed.
- Many leaked credentials remain active and could allow attackers ongoing access to company systems.
Read the Full Article
This is a fact-based summary from The Actual News. Click below to read the complete story directly from the original source.