Close Menu
MyAppsPlus

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Last day to score Anker’s 100W Smart Display Charger at 30% off via Amazon

    September 14, 2026

    Local AI servers look set to take on the cloud, and I’m all for it

    September 14, 2026

    A Vinyl Bar in Shibuya is a startup offering fun music apps without any AI prompting

    September 14, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram
    MyAppsPlusMyAppsPlus
    Monday, September 14
    • Home
    • Breaking Tech
    • Apps & Software
    • AI & Automation
    • Android
    • iPhone & iOS
    • More
      • Reviews
      • How-To Guides
      • Deals & Discounts
      • Shop
    MyAppsPlus
    Home»Reviews»Massive supply-chain attack sees terabytes of data belonging to some of the world’s biggest and most sensitive organizations leaked online
    Reviews

    Massive supply-chain attack sees terabytes of data belonging to some of the world’s biggest and most sensitive organizations leaked online

    myappsplusBy myappsplusAugust 21, 2026003 Mins Read
    Share Facebook Twitter Pinterest Copy Link LinkedIn Tumblr Email Telegram WhatsApp
    Follow Us
    Google News Flipboard
    Massive supply-chain attack sees terabytes of data belonging to some of the world’s biggest and most sensitive organizations leaked online
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link
    • More than 2,500 organizations, including Cisco, Samsung, AWS, Airbus U.S. Space & Defense, Thales, and the London Stock Exchange Group, have credentials harvested during a supply-chain attack on LiteLLM
    • LiteLLM was not directly hacked by the hacking group TeamPCP, which found their way in thanks to a compromised build of an open-source security scanner
    • Some of the credentials still work, nearly five months after the original breach, indicating that there is still a persistent security risk until they are changed

    Security firms CloudSEK and Hudson Rock have claimed more than 2,500 organizations have had credentials harvested in a supply-chain attack on LiteLLM.

    LiteLLM, an openge models into a single OpenAI-compatible format, was not directly compromised in the attack, as hackers targeted a known vulnerability in Aqua Security’s Trivy

    The list included many large and critical service providers, including but not limited to Cisco, Samsung, Salesforce, and Amazon Web Services, as well as Airbus U.S. Space & Defense, Thales Group, Deutsche Bahn, Munich Re, and the London Stock Exchange Group.

    An attack that is still a concern nearly five months later

    The original attack occurred on March 24 2026 and was spearheaded by a financially motivated hacking group called TeamPCP, which compromised Trivy, an open

    The modified package, which was subsequently downloaded and ‘invited’ in by LiteLLM without checking its ID- an automated process that essentially allowed a poisoned version of the trusted tool in- gained server administrator privileges and then installed a stealer.

    The stealer compromised credentials and secrets far more valuable than corporate data, including Cloud keys, SSH keys, Kubernetes tokens, environment variables, repository and package-publishing tokens, and AI provider keys.

    These are arguably worse from a security standpoint than a singular breach because of both the scale of the attack and the fact that hackers now had a ‘key’ to many security doors rather than having to run exploits to get there.

    The victim-scale research done by CloudSEK was further corroborated the following day by Hudson Rock, and it painted a grim picture of what was still an outstanding issue nearly 5 months after the original attack.

    The irony is that some of the credentials still work: Independent researcher Kevin Beaumont said some of the compromised keys were still valid after he tested them, even as the impacted organization insisted it had ‘rotated’ those keys to new ones.

    CloudSEK’s figures indicate 2,500-plus companies and 434,000 CI/CD pipelines were compromised, while Hudson Rock has released a 153 GB archive of the exfiltrated material after examining a 195 TB file it had obtained. Both firms are running domain-lookup tools so organizations can check their own exposure online.

    Whether these revelations lead organizations to double-check their use of AI tools in multiple mission-critical instances that could compromise not only customer data but their own trade secrets down the line remains to be seen.

    attack massive Pro Security supplychain
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    myappsplus
    • Website

    Related Posts

    Local AI servers look set to take on the cloud, and I’m all for it

    September 14, 2026

    This white 32GB Corsair Vengeance RGB DDR5-6000 RAM kit gets a welcome discount using a special coupon at Newegg

    September 14, 2026

    ‘We’ve ruined many of James’ Persian rugs over the years’ — Dyson designer shares the development secrets of the brand’s new robovac lineup

    September 14, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    The 6 AI-free Linux distros I recommend most

    August 19, 20264 Views

    AI, automation, robot dogs ensure on-site nuclear safety

    September 7, 20262 Views

    This tiny AI box could save me from upgrading my perfectly good laptop

    September 6, 20262 Views
    Latest Reviews

    Fairphone officially starts selling its new repairable Android phone in the US for $649

    myappsplusAugust 18, 2026

    Best Patch Management Software & Tools 2026

    myappsplusAugust 18, 2026

    Anthro Energy breaks ground on factory that could pave the road to solid-state batteries

    myappsplusAugust 18, 2026
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    Fairphone officially starts selling its new repairable Android phone in the US for $649

    August 18, 20260 Views

    Best Patch Management Software & Tools 2026

    August 18, 20260 Views

    Anthro Energy breaks ground on factory that could pave the road to solid-state batteries

    August 18, 20260 Views
    Our Picks

    Last day to score Anker’s 100W Smart Display Charger at 30% off via Amazon

    September 14, 2026

    Local AI servers look set to take on the cloud, and I’m all for it

    September 14, 2026

    A Vinyl Bar in Shibuya is a startup offering fun music apps without any AI prompting

    September 14, 2026

    Subscribe to Updates

    Subscribe to our newsletter and get the latest tech news, app updates, AI trends, smartphone reviews, and exclusive deals delivered straight to your inbox.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Get In Touch
    • Disclaimer
    • Privacy Policy
    • Terms & Conditions
    © 2026 MyAppsPlus. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.