PulseAugur
EN
LIVE 22:45:30

Terabytes of credentials leaked in massive AI supply-chain attack · 2 sources tracked

A significant supply-chain attack has exposed terabytes of credentials from over 2,500 organizations, including major tech companies like Microsoft and Amazon. The breach occurred through compromised versions of LiteLLM, an open-source tool for AI development, which were inadvertently downloaded from the Python Package Index. Security firms CloudSEK and Hudson Rock discovered the leaked data, which included cloud keys, repository tokens, and SSH keys, after analyzing a massive 195TB file. The attack, attributed to a group known as TeamPCP, exploited vulnerabilities in the software supply chain, highlighting poor security practices in organizations rushing to adopt AI technologies. AI

IMPACT Highlights critical security vulnerabilities in AI development tools, potentially slowing enterprise adoption due to trust concerns.

RANK_REASON The cluster describes a security incident involving a software tool, not a core AI release or research.

Read on Ars Technica — AI →

AI-generated summary · Google Gemini · from 2 sources. How we write summaries →

Terabytes of credentials leaked in massive AI supply-chain attack · 2 sources tracked

COVERAGE [2]

  1. Ars Technica — AI TIER_1 English(EN) · Dan Goodin ·

    Terabytes of credentials leaked in massive supply-chain attack

    The data was scraped and exfiltrated from 2,500 users of a compromised AI package.

  2. Mastodon — sigmoid.social TIER_1 English(EN) · [email protected] ·

    📰 Terabytes of credentials leaked in massive supply-chain attack The data was scraped and exfiltrated from 2,500 users of a compromised AI package. 📰 Source: Ar

    📰 Terabytes of credentials leaked in massive supply-chain attack The data was scraped and exfiltrated from 2,500 users of a compromised AI package. 📰 Source: Ars Technica 🔗 Link: https://arstechnica.com/security/2026/08/terabytes-of-credentials-leaked-in-massive-supply-chain-atta…