Negócios em Emersão  ·  Vamos Emergir?  ·  Cadastre-se e ganhe 50 REC de bonus

Terabytes of credentials leaked in massive supply-chain attack

Redação Recifes
49 visualizações
Terabytes of credentials leaked in massive supply-chain attack

Terabytes of credentials leaked in massive supply-chain attack. The data was scraped and exfiltrated from 2,500 users of a compromised AI package.

O que aconteceu

Terabytes worth of credentials, many belonging to the world’s biggest and most sensitive organizations, have been exposed in a supply-chain attack on LiteLLM, an open source tool that streamlines AI-driven software development.

Microsoft, Amazon, Cisco, Samsung, and Salesforce are only a handful of the entities whose access secrets were exposed.

The revelation was posted on Tuesday and Wednesday by security firms CloudSEK and Hudson Rock.

Por que importa

Os números em evidência (40 mi) ajudam a medir o impacto no dia a dia de empresas e leitores de Tech.

Consequência prática

CloudSEK said it found cloud keys, repository tokens, SSH keys, Kubernetes secrets, package publishing credentials, environment variables, and AI provider keys that could allow attackers to gain access to more than 2,500 organizations.

40 minutes is all it takes The credentials were extracted during a 40-minute window in March while the victims used compromised versions of LiteLLM downloaded from the package’s official location in the Python Package Index repository.

Hudson Rock said it made the discovery after analyzing a 195TB file that it obtained.

Neither firm identified the source of the information.Read full article Comments

Terabytes worth of credentials, many belonging to the world’s biggest and most sensitive organizations, have been exposed in a supply-chain attack on LiteLLM, an open source tool that streamlines AI-driven software development. Com base em 40 mi, o movimento reforça a leitura de que decisões em Tech precisam ser acompanhadas com atenção aos dados e ao desfecho concreto.

Microsoft, Amazon, Cisco, Samsung, and Salesforce are only a handful of the entities whose access secrets were exposed. Com base em 40 mi, o movimento reforça a leitura de que decisões em Tech precisam ser acompanhadas com atenção aos dados e ao desfecho concreto.

The revelation was posted on Tuesday and Wednesday by security firms CloudSEK and Hudson Rock. Com base em 40 mi, o movimento reforça a leitura de que decisões em Tech precisam ser acompanhadas com atenção aos dados e ao desfecho concreto.

CloudSEK said it found cloud keys, repository tokens, SSH keys, Kubernetes secrets, package publishing credentials, environment variables, and AI provider keys that could allow attackers to gain access to more than 2,500 organizations. Com base em 40 mi, o movimento reforça a leitura de que decisões em Tech precisam ser acompanhadas com atenção aos dados e ao desfecho concreto.

40 minutes is all it takes The credentials were extracted during a 40-minute window in March while the victims used compromised versions of LiteLLM downloaded from the package’s official location in the Python Package Index repository. Com base em 40 mi, o movimento reforça a leitura de que decisões em Tech precisam ser acompanhadas com atenção aos dados e ao desfecho concreto.

Hudson Rock said it made the discovery after analyzing a 195TB file that it obtained. Com base em 40 mi, o movimento reforça a leitura de que decisões em Tech precisam ser acompanhadas com atenção aos dados e ao desfecho concreto.

Artigo originalmente publicado em arstechnica.com
Compartilhar:

Comentários

Seja o primeiro a comentar!