5 pointsby Bender7 hours ago1 comment
  • esseph3 hours ago
    > In all, both security firms said some 434,000 CI/CD (continuous integration/continuous delivery) software pipelines had credentials exposed after running the compromised LiteLLM versions. In many cases, researchers at CloudSEK and Hudson Rock had trouble identifying the organizations the credentials belonged to. For instance, an email address in the dump from the domain @siriusxm.com ultimately didn’t indicate a breach at the satellite broadcaster, but rather one within the infrastructure of SiriusXM subsidiary AdsWizz.

    Short List:

    Nvidia Corporation

    Amazon Web Services (AWS)

    Samsung Electronics

    samsung.com

    Salesforce, Inc.

    Cisco Systems, Inc.

    F. Hoffmann-La Roche AG

    ServiceNow

    Siemens AG

    S&P Global

    Airbus US Space & Defense

    John Deere

    Regeneron Pharmaceuticals, Inc.

    London Stock Exchange Group (LSEG)

    Thomson Reuters

    FedEx

    Munich Remunichre.com

    MediaTek Inc.

    Volkswagen AG

    Deloitte

    The Kroger Co.

    Siemens Energy

    Thales Group

    X Corp (Twitter)

    Zscaler, Inc.

    Epic Games

    Orange S.A.

    HP Inc.

    Philips

    Fortum Oyj

    Vodafone Group Plc

    Carl Zeiss AG

    Deutsche Bahn AG

    NGINX, Inc.

    BT Group

    Liebherr

    Krungthai Bank Public Company Limited

    Roku, Inc.

    Full List:

    https://exposure.cloudsek.com/ai-supply-chain-incident