Hacker News

Terabytes of credentials leaked in supply-chain attack

5 points by Bender ago | 1 comments

esseph [-]

> In all, both security firms said some 434,000 CI/CD (continuous integration/continuous delivery) software pipelines had credentials exposed after running the compromised LiteLLM versions. In many cases, researchers at CloudSEK and Hudson Rock had trouble identifying the organizations the credentials belonged to. For instance, an email address in the dump from the domain @siriusxm.com ultimately didn’t indicate a breach at the satellite broadcaster, but rather one within the infrastructure of SiriusXM subsidiary AdsWizz.

Short List:

Nvidia Corporation

Amazon Web Services (AWS)

Samsung Electronics

samsung.com

Salesforce, Inc.

Cisco Systems, Inc.

F. Hoffmann-La Roche AG

ServiceNow

Siemens AG

S&P Global

Airbus US Space & Defense

John Deere

Regeneron Pharmaceuticals, Inc.

London Stock Exchange Group (LSEG)

Thomson Reuters

FedEx

Munich Remunichre.com

MediaTek Inc.

Volkswagen AG

Deloitte

The Kroger Co.

Siemens Energy

Thales Group

X Corp (Twitter)

Zscaler, Inc.

Epic Games

Orange S.A.

HP Inc.

Philips

Fortum Oyj

Vodafone Group Plc

Carl Zeiss AG

Deutsche Bahn AG

NGINX, Inc.

BT Group

Liebherr

Krungthai Bank Public Company Limited

Roku, Inc.

Full List:

https://exposure.cloudsek.com/ai-supply-chain-incident