跳到主内容
精选80Ars Technica AI(RSS)行业动态

LiteLLM供应链攻击致海量凭据泄露,波及微软亚马逊等巨头

Terabytes of credentials leaked in massive supply-chain attack

原文
推荐理由

AI供应链安全事件,波及多家科技巨头,做AI开发的同学务必检查依赖来源,及时轮换凭据。

Terabytes worth of credentials, many belonging to the world’s biggest and most sensitive organizations, have been exposed in a supply-chain attack on LiteLLM, an open source tool that streamlines AI-driven software development. Microsoft, Amazon, Cisco, Samsung, and Salesforce are only a handful of the entities whose access secrets were exposed.

数TB的凭据(其中许多属于世界上最大、最敏感的组织)在针对LiteLLM的供应链攻击中被曝光,LiteLLM是一款简化AI驱动软件开发的开源工具。微软、亚马逊、思科、三星和Salesforce只是其访问机密被曝光的实体中的一小部分。

The revelation was posted on Tuesday and Wednesday by security firms CloudSEK and Hudson Rock. CloudSEK said it found cloud keys, repository tokens, SSH keys, Kubernetes secrets, package publishing credentials, environment variables, and AI provider keys that could allow attackers to gain access to more than 2,500 organizations.

这一消息于周二和周三由安全公司CloudSEK和Hudson Rock发布。CloudSEK表示,它发现了云密钥、仓库令牌、SSH密钥、Kubernetes机密、软件包发布凭据、环境变量和AI提供商密钥,这些可能允许攻击者访问超过2500个组织。

40 minutes is all it takes

只需40分钟

The credentials were extracted during a 40-minute window in March while the victims used compromised versions of LiteLLM downloaded from the package’s official location in the Python Package Index repository. Hudson Rock said it made the discovery after analyzing a 195TB file that it obtained. Neither firm identified the source of the information.

这些凭据是在3月份一个40分钟的时间窗口内被提取的,当时受害者使用了从Python包索引仓库中该软件包的官方位置下载的受损LiteLLM版本。Hudson Rock表示,它在分析获得的一个195TB文件后发现了这一情况。两家公司均未指明信息来源。

Read full article

阅读全文

Comments

评论

更进一步:量化金融体系

看懂新闻只是起点——沿量化金融路径,把它变成能交付的工程能力

进入量化体系 →

相似阅读

另一事件,读法相近