
Terabytes worth of credentials, many belonging to the world’s biggest and most sensitive organizations, have been exposed in a supply-chain attack on LiteLLM, an open source tool that streamlines AI-driven software development. Microsoft, Amazon, Cisco, Samsung, and Salesforce are only a handful of the entities whose access secrets were exposed. The revelation was posted on Tuesday and Wednesday by security firms CloudSEK and Hudson Rock. CloudSEK said it found cloud keys, repository tokens, SSH
A supply-chain attack compromised an open source AI tool called LiteLLM, exposing sensitive credentials belonging to thousands of organizations including major technology and industrial companies. During a 40-minute window in March, attackers distributed malicious versions of the software through official repositories, which then scraped and exfiltrated sensitive data such as cloud keys, access tokens, and passwords from affected machines. The attack was facilitated by a previous compromise of another widely used software tool, and security researchers attribute the scale of the breach to organizations' rush to integrate AI into their systems combined with poor security practices in software development pipelines. Both affected organizations and the cybersecurity industry have been advised to immediately rotate all exposed credentials and audit their environments for the compromised software versions.

When Twitch announced that streamers could opt out, thousands of users questioned why their content was being used to train AI models in the first place.

Tim O’Reilly built a publishing empire that AI is helping to destroy. Yet he loves AI—as long as it’s open source.

A judge has identified what appears to be the first time a US plaintiff has attempted to hide text in court filings that only an artificial intelligence system can read in a bid to win a case. In a decision published last week, Connecticut judge Walter Spader Jr. confirmed that the hidden text had no impact in a case where a man alleged a healthcare provider was improperly withholding access to records. The court weighed his filing on the merits, Spader said, but nevertheless, the attempted atta
Want to go deeper than the news? Explore live, cohort-based AI courses taught by practitioners.
Browse AI courses on Maven