Terabytes worth of credentials, many belonging to the world’s biggest and most sensitive organizations, have been exposed in a supply-chain attack on LiteLLM, an open source tool that streamlines A- driven software development. Microsoft, Amazon, Cisco, Samsung, and Salesforce are only a handful of the entities whose access secrets were exposed.
The revelation was posted on Tuesday and Wednesday by security firms CloudSEK and Hudson Rock. CloudSEK said it found cloud keys, repository tokens, SSH keys, Kubernetes secrets, package publishing credentials, environment variables, and AlI provider keys that could allow attackers to gain access to more than 2,500 organizations.
The credentials were extracted during a 40-minute window in March while the victims used compromised versions of LiteLLM downloaded from the package’s official location in the Python Package Index repository. Hudson Rock said it made the discovery after analyzing a 195TB file that it obtained. Neither firm identified the source of the information.



Possible IT attacks are so sophisticated, that for example rowvolt uses out of os processor voltage regulation to target specific AES cycles to produce errors so the initial password can be decoded. Row Hammer is an attack where by hammering ram spaces with random numbers you can do electric but flips in adjacent ram transistors wich make the system write Infos in wrong address spaces. Both attacks are physical attacks on hardware through software and impossible to defend against. However the in nature attacks are mostly social profiling and not software related. Software related attacks are seldom in the wild. Even the attack here is basically a social engineering attack because ppl installed Maleware on their systems by their own accord.
Info