Terabytes of credentials leaked in massive supply-chain attack



The firm advised all those affected to perform “aggressive credential revocation,” assume any secret accessible to the LiteLLM environment is compromised, invalidate and rotate all cloud keys, Kubernetes service account tokens, and GitLab/GitHub PATs, and audit logging and egress filtering.

As a cautionary tale, CloudSEK said that Trivy developers rotated, but failed to fully revoke an automation token over a 20-day window. The lapse gave the attackers a nearly three-week period to force-push malicious code to third-party builds that used the vulnerability scanner. As Beaumont observed, organizations’ rush to integrate AI into their software delivery systems has also greatly contributed to the scale of the damage.

Update:There are already signs that some of the affected organizations aren’t taking the disclosure with the seriousness warranted. After this post went live, Beaumont reported:

These creds date from about March. One of the orgs impacted told me they’d rotated them all and it’s a nothingburger, so I looked at their responsible disclosure policy, it allows trying creds, so I tried them all. Almost every one worked. Submitted report. One of the biggest US techcos.

Ultimately, the new revelations concerning the LiteLLM supply-chain attack underscore the growing threat of such campaigns and hence the importance of maintaining vigilance around the use of open source software that, when infected, can spread rapidly across the Internet.

“The key takeaway is how supply chains have evolved to make a single upstream breach affect thousands of companies simultaneously,” Alon Gal, co-founder and chief technology officer of Hudson Rock, wrote in an email. “A window of roughly 40 minutes in which the LiteLLM dependency was hacked led to over 430,000 instances in which millions of secrets were harvested. This magnitude pushes us into a completely new world regarding the type of response required from the cybersecurity industry.”

Post updated to add image.



Source link

  • Related Posts

    Apple Faces Lawsuit Over iCloud Private Relay Vulnerability

    The revelation that Apple’s iCloud Private Relay feature hasn’t been as secure as Apple says has spawned a lawsuit against the iPhone maker. Last week, a blog post by Talal Haj Bakry…

    Pixel 11 event live blog: Let’s watch Trevor Noah introduce Google’s new phones

    It’s almost time for the Made by Google keynote, where the company will show off the brand-new Pixel hardware it announced today. Like last year, it’ll be a celebrity-packed live…

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    You Missed

    Man linked to alleged gun-for-hire network in Toronto facing new robbery charges

    Man linked to alleged gun-for-hire network in Toronto facing new robbery charges

    The exorbitant privilege of the periodic table

    Apple Faces Lawsuit Over iCloud Private Relay Vulnerability

    Apple Faces Lawsuit Over iCloud Private Relay Vulnerability

    Runescape Congratulates Player Who Reached Level 99 Fishing Catching Only Shrimp and Anchovies

    Runescape Congratulates Player Who Reached Level 99 Fishing Catching Only Shrimp and Anchovies

    Bank of America commits $250bn to US projects in boost to ‘America First’ agenda

    ICE’s plan to give officers electric shock gloves draws outrage and fears of misuse

    ICE’s plan to give officers electric shock gloves draws outrage and fears of misuse