Topic: ci/cd pipeline risks
-
LiteLLM supply chain attack exposes 153GB of stolen credentials
Hudson Rock obtained and analyzed a 153GB trove of stolen credentials from the LiteLLM supply chain attack, exposing secrets from thousands of major organizations like AWS, Samsung, and Cisco, and is conducting a global ethical disclosure campaign to help victims before the data is weaponized. Th...
Read More » -
Dark Web Holds Early Clues to Supply-Chain Attacks
Early warning signs of software supply-chain attacks often appear on the dark web as posts advertising GitHub access, source code, API keys, and OAuth tokens, with the real danger lying in the trust relationships these exposures touch. A recent Flare investigation highlights that GitHub-related a...
Read More »