PulseAugur
中
实时 11:36:05
English(EN) Terabytes of credentials leaked in massive supply-chain attack The data was scraped and exfiltrated from 2,500 users of a compromised AI package. https:// arste

LiteLLM AI供应链攻击泄露数TB凭证 · 追踪8个来源

一次针对开源AI开发工具LiteLLM的重大供应链攻击导致数TB敏感凭证暴露。从Python Package Index下载的受损LiteLLM版本包含恶意代码,该代码抓取并导出了包括云密钥、存储库令牌和AI提供商密钥在内的数据。此次泄露事件归咎于一个主要由青少年组成的团伙,影响了约2500个组织,包括Microsoft、Amazon、Cisco、Samsung和Salesforce等大型科技公司,影响了超过430,000个CI/CD管道。 AI

影响 凸显了AI开发供应链中的关键漏洞,强调了加强AI工具和依赖项安全实践的必要性。

排序理由 该集群描述了一起涉及广泛使用的软件工具的安全事件,而不是新的模型发布或核心AI研究。

在 Mastodon — mastodon.social 阅读 →

AI 生成摘要 · Google Gemini · 来自 8 个来源。 我们如何撰写摘要 →

LiteLLM AI供应链攻击泄露数TB凭证 · 追踪8个来源

本文如何被排名

Signal score
0 / 100
Composite score across the factors below. Higher = stronger signal that this story matters right now.
Newsworthiness bucket
Tool
该集群描述了一起涉及广泛使用的软件工具的安全事件,而不是新的模型发布或核心AI研究。
Source corroboration
8 independent sources
Strong cross-source corroboration — multiple independent publishers covered this within the clustering window.
Topics
product, safety
Editorial topic classification. Feeds into how the story surfaces on /topic/<slug> hub pages and into the per-entity coverage mix.
AI-industry relevance
High
Clearly on-topic for AI-industry coverage.
Story freshness
48 days old
Aged out of breaking-news scoring windows; ranking reflects the durable signal from the full source set.

完整方法见我们的编辑标准。

报道来源 [8]

  1. Ars Technica — AI TIER_1 English(EN) · Dan Goodin ·

    海量凭证在一次大规模供应链攻击中泄露

    The data was scraped and exfiltrated from 2,500 users of a compromised AI package.

  2. Mastodon — sigmoid.social TIER_1 English(EN) · [email protected] ·

    📰 海量凭证在一次大规模供应链攻击中泄露 此次泄露的数据是从一个受损的AI软件包的2500名用户处抓取并导出的。📰 来源:Ar

    📰 Terabytes of credentials leaked in massive supply-chain attack The data was scraped and exfiltrated from 2,500 users of a compromised AI package. 📰 Source: Ars Technica 🔗 Link: https://arstechnica.com/security/2026/08/terabytes-of-credentials-leaked-in-massive-supply-chain-atta…

  3. Mastodon — fosstodon.org TIER_1 English(EN) · [email protected] ·

    Apparently, it takes less than an hour to get a massive amount of credentials. Terabytes of credentials leaked in massive supply-chain attack https:// arstechni

    Apparently, it takes less than an hour to get a massive amount of credentials. Terabytes of credentials leaked in massive supply-chain attack https:// arstechnica.com/security/2026/ 08/terabytes-of-credentials-leaked-in-massive-supply-chain-attack/ # Credentials # Leak # Vulnerab…

  4. Mastodon — fosstodon.org TIER_1 English(EN) · [email protected] ·

    嘿,各位!超过2500家大型财富500强类型组织的数TB凭证在 #LiteLLM 的供应链攻击中暴露。该

    Hey everyone! Terabytes worth of # credentials , for more than 2500 massive Fortune 500 type orgs have been exposed in a supply-chain attack on # LiteLLM . The breach was reported Tuesday and Wednesday by security firms # CloudSEK and # HudsonRock . (Links below) CloudSEK said it…

  5. Mastodon — fosstodon.org TIER_1 English(EN) · vforberger ·

    海量凭证在重大供应链攻击中泄露,涉及litellm

    https:// arstechnica.com/security/2026/ 08/terabytes-of-credentials-leaked-in-massive-supply-chain-attack/ # AI # SecurityBreach # SupplyChain # litellm “A window of roughly 40 minutes in which the LiteLLM dependency was hacked led to over 430,000 instances in which millions of s…

  6. Mastodon — fosstodon.org TIER_1 English(EN) · [email protected] ·

    大规模供应链攻击泄露数万亿字节凭证 数万亿字节凭证泄露,其中许多属于全球最大、最敏感的组织

    Terabytes of credentials leaked in massive supply-chain attack Terabytes worth of credentials, many belonging to the world’s biggest and most sensitive organizations, have been exposed in a supply-chain attack on LiteLLM, a tool that streamlines AI-driven software development. # …

  7. Mastodon — fosstodon.org TIER_1 English(EN) · [email protected] ·

    供应链攻击正成为凭证窃取机器。据报道,针对一个受损AI软件包的新攻击窃取并泄露了数TB数据

    Supply-chain attacks are becoming credential-exfiltration machines. A new attack against a compromised AI package reportedly scraped and exfiltrated terabytes of credentials and sensitive data from roughly 2,500 users. The bigger lesson isn’t just about one malicious package. Mod…

  8. Mastodon — mastodon.social TIER_1 English(EN) · [email protected] ·

    海量凭证在大型供应链攻击中泄露 该数据是从受损AI软件包的2500名用户处抓取并导出的。https:// arste

    Terabytes of credentials leaked in massive supply-chain attack The data was scraped and exfiltrated from 2,500 users of a compromised AI package. https:// arstechnica.com/security/2026/ 08/terabytes-of-credentials-leaked-in-massive-supply-chain-attack/ # Tech # AI # Cybersecurity…