LiteLLM cyberattack exposes over 2,500 companies to risk
More than 2,500 companies could have been exposed by a cyberattack against LiteLLM, a tool used for working with artificial intelligence models.
The incident may have also potentially affected about 434,000 systems used by companies to develop and update their programs.
The attack took place in March, and the perpetrators introduced malicious code into two versions of LiteLLM that were available for about 40 minutes. The goal was to exploit these programs to access information stored on the computers and systems of the companies that installed them.
According to CloudSEK, which has published a report on the incident detailing the number of victims, the attackers were able to search for passwords and access keys to cloud services, code repositories, internal systems, and artificial intelligence services.
"The stolen object was cloud keys, repository tokens, SSH keys, Kubernetes secrets, package publishing credentials, environment variables, and AI provider keys," explains the company.
Among the companies listed as potentially exposed are names like AWS, Samsung, Cisco, Salesforce, Siemens, Airbus, FedEx, Volkswagen, Deloitte, Orange, Vodafone, Thales, and Epic Games.
CloudSEK clarifies that appearing on their list does not mean that these companies have necessarily been hacked, but that there are indications of possible exposure that should be investigated.
Additionally, the firm recommends organizations check if they used the affected versions and, if so, change the passwords and keys that may have been within reach of the attackers. Deleting the malicious program is not enough, as the stolen passwords could remain functional for weeks or months.
The case of LiteLLM is a clear example of the dangers of supply chain attacks, where criminals do not need to directly enter a large company but can first attack one of its trusted providers, programs, or tools.
In this way, a single compromised component can serve as an entry point to many organizations at the same time. Thus, it is increasingly evident that security no longer depends solely on protecting one's own systems, but it is also necessary to know and monitor what software and services companies use, as an apparently legitimate tool can become the weakest link in the entire chain.
Related Stories
AI News
System helps humans predict when self
24 minutes ago
AI News
Hundreds protest outside Chapel Hill's G20 Innovation Ministerial, criticizing artificial intelligence
24 minutes ago
AI News
The most in
53 minutes ago
AI News
Fake 10 Downing Street listing exposes 'unfit' Booking.com, says consumer group
54 minutes ago
AI News
Most Banks Wait Six Years for AI Payback. Discovery Didn’t.
1 hour ago
AI News
US and Big Tech Advocate Looser AI Rules at G20 Gathering
2 hours ago
AI News
Anthropic Admits Security Failures Behind Claude Hacking Incidents
2 hours ago
AI News
The quiet regionalisation of AI governance
2 hours ago