PulseAugur
实时 22:45:30
English(EN) Terabytes of credentials leaked in massive supply-chain attack

数TB凭证在一次大规模AI供应链攻击中泄露 · 已追踪2个来源

一次重大的供应链攻击暴露了来自超过2500个组织的数TB凭证,其中包括Microsoft和Amazon等科技巨头。此次泄露是通过Python Package Index上无意下载的LiteLLM(一款开源AI开发工具)的受损版本发生的。安全公司CloudSEK和Hudson Rock在分析了195TB的庞大数据文件后发现了泄露的数据,其中包括云密钥、存储库令牌和SSH密钥。此次攻击归因于一个名为TeamPCP的组织,利用了软件供应链中的漏洞,凸显了在仓促采用AI技术的组织中存在的安全实践不当问题。 AI

影响 凸显了AI开发工具中存在的关键安全漏洞,可能因信任问题减缓企业的采用速度。

排序理由 该集群描述了一起涉及软件工具的安全事件,而非核心AI发布或研究。

在 Ars Technica — AI 阅读 →

AI 生成摘要 · Google Gemini · 来自 2 个来源。 我们如何撰写摘要 →

数TB凭证在一次大规模AI供应链攻击中泄露 · 已追踪2个来源

报道来源 [2]

  1. Ars Technica — AI TIER_1 English(EN) · Dan Goodin ·

    Terabytes of credentials leaked in massive supply-chain attack

    The data was scraped and exfiltrated from 2,500 users of a compromised AI package.

  2. Mastodon — sigmoid.social TIER_1 English(EN) · [email protected] ·

    📰 Terabytes of credentials leaked in massive supply-chain attack The data was scraped and exfiltrated from 2,500 users of a compromised AI package. 📰 Source: Ar

    📰 Terabytes of credentials leaked in massive supply-chain attack The data was scraped and exfiltrated from 2,500 users of a compromised AI package. 📰 Source: Ars Technica 🔗 Link: https://arstechnica.com/security/2026/08/terabytes-of-credentials-leaked-in-massive-supply-chain-atta…