home.social

#cloudsek — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #cloudsek, aggregated by home.social.

fetched live
  1. Hey everyone! Terabytes worth of #credentials, for more than 2500 massive Fortune 500 type orgs have been exposed in a supply-chain attack on #LiteLLM.

    The breach was reported Tuesday and Wednesday by security firms #CloudSEK and #HudsonRock. (Links below) CloudSEK said it found cloud keys, repository tokens, #SSH keys, #Kubernetes secrets, package publishing credentials, environment variables, and AI provider #keys.

    This, in the world of #infosec, is called A Bad Thing. The fact that some of the credentials are still live, is mind boggling.

    #ai #security #SupplyChainAttack #hack

    cloudsek.com/blog/ai-supply-ch

    Companies exposed: exposure.cloudsek.com/ai-suppl

    hudsonrock.com/blog/largest-ai

    ArsTecnica overview: arstechnica.com/security/2026/

  2. Hey everyone! Terabytes worth of #credentials, for more than 2500 massive Fortune 500 type orgs have been exposed in a supply-chain attack on #LiteLLM.

    The breach was reported Tuesday and Wednesday by security firms #CloudSEK and #HudsonRock. (Links below) CloudSEK said it found cloud keys, repository tokens, #SSH keys, #Kubernetes secrets, package publishing credentials, environment variables, and AI provider #keys.

    This, in the world of #infosec, is called A Bad Thing. The fact that some of the credentials are still live, is mind boggling.

    #ai #security #SupplyChainAttack #hack

    cloudsek.com/blog/ai-supply-ch

    Companies exposed: exposure.cloudsek.com/ai-suppl

    hudsonrock.com/blog/largest-ai

    ArsTecnica overview: arstechnica.com/security/2026/

  3. Hey everyone! Terabytes worth of #credentials, for more than 2500 massive Fortune 500 type orgs have been exposed in a supply-chain attack on #LiteLLM.

    The breach was reported Tuesday and Wednesday by security firms #CloudSEK and #HudsonRock. (Links below) CloudSEK said it found cloud keys, repository tokens, #SSH keys, #Kubernetes secrets, package publishing credentials, environment variables, and AI provider #keys.

    This, in the world of #infosec, is called A Bad Thing. The fact that some of the credentials are still live, is mind boggling.

    #ai #security #SupplyChainAttack #hack

    cloudsek.com/blog/ai-supply-ch

    Companies exposed: exposure.cloudsek.com/ai-suppl

    hudsonrock.com/blog/largest-ai

    ArsTecnica overview: arstechnica.com/security/2026/

  4. Hey everyone! Terabytes worth of #credentials, for more than 2500 massive Fortune 500 type orgs have been exposed in a supply-chain attack on #LiteLLM.

    The breach was reported Tuesday and Wednesday by security firms #CloudSEK and #HudsonRock. (Links below) CloudSEK said it found cloud keys, repository tokens, #SSH keys, #Kubernetes secrets, package publishing credentials, environment variables, and AI provider #keys.

    This, in the world of #infosec, is called A Bad Thing. The fact that some of the credentials are still live, is mind boggling.

    #ai #security #SupplyChainAttack #hack

    cloudsek.com/blog/ai-supply-ch

    Companies exposed: exposure.cloudsek.com/ai-suppl

    hudsonrock.com/blog/largest-ai

    ArsTecnica overview: arstechnica.com/security/2026/

  5. Hey everyone! Terabytes worth of #credentials, for more than 2500 massive Fortune 500 type orgs have been exposed in a supply-chain attack on #LiteLLM.

    The breach was reported Tuesday and Wednesday by security firms #CloudSEK and #HudsonRock. (Links below) CloudSEK said it found cloud keys, repository tokens, #SSH keys, #Kubernetes secrets, package publishing credentials, environment variables, and AI provider #keys.

    This, in the world of #infosec, is called A Bad Thing. The fact that some of the credentials are still live, is mind boggling.

    #ai #security #SupplyChainAttack #hack

    cloudsek.com/blog/ai-supply-ch

    Companies exposed: exposure.cloudsek.com/ai-suppl

    hudsonrock.com/blog/largest-ai

    ArsTecnica overview: arstechnica.com/security/2026/

  6. 𝐃𝐨𝐮𝐛𝐭𝐬 𝐎𝐯𝐞𝐫 𝐁𝐚𝐬𝐡𝐞’𝐬 𝐂𝐥𝐚𝐢𝐦𝐬: 𝐓𝐞𝐜𝐡𝐧𝐢𝐜𝐚𝐥 𝐀𝐧𝐚𝐥𝐲𝐬𝐢𝐬 𝐚𝐧𝐝 𝐎𝐩𝐞𝐧 𝐐𝐮𝐞𝐬𝐭𝐢𝐨𝐧𝐬

    What emerged from this follow-up inquiry highlights significant discrepancies between the statements published on the group’s blog and the technical characteristics of the data examined. Despite our additional questions, no verifiable evidence was provided to substantiate the claims. Instead, we were told that authenticity could be confirmed through the purchase of the stolen database — a proposal we firmly rejected.

    suspectfile.com/doubts-over-ba

    #APT73 #Bashe #CloudSEK #IndianBank #IndonesianBank #LineBank #Ransomware

  7. 𝐃𝐨𝐮𝐛𝐭𝐬 𝐎𝐯𝐞𝐫 𝐁𝐚𝐬𝐡𝐞’𝐬 𝐂𝐥𝐚𝐢𝐦𝐬: 𝐓𝐞𝐜𝐡𝐧𝐢𝐜𝐚𝐥 𝐀𝐧𝐚𝐥𝐲𝐬𝐢𝐬 𝐚𝐧𝐝 𝐎𝐩𝐞𝐧 𝐐𝐮𝐞𝐬𝐭𝐢𝐨𝐧𝐬

    What emerged from this follow-up inquiry highlights significant discrepancies between the statements published on the group’s blog and the technical characteristics of the data examined. Despite our additional questions, no verifiable evidence was provided to substantiate the claims. Instead, we were told that authenticity could be confirmed through the purchase of the stolen database — a proposal we firmly rejected.

    suspectfile.com/doubts-over-ba

    #APT73 #Bashe #CloudSEK #IndianBank #IndonesianBank #LineBank #Ransomware

  8. 𝐃𝐨𝐮𝐛𝐭𝐬 𝐎𝐯𝐞𝐫 𝐁𝐚𝐬𝐡𝐞’𝐬 𝐂𝐥𝐚𝐢𝐦𝐬: 𝐓𝐞𝐜𝐡𝐧𝐢𝐜𝐚𝐥 𝐀𝐧𝐚𝐥𝐲𝐬𝐢𝐬 𝐚𝐧𝐝 𝐎𝐩𝐞𝐧 𝐐𝐮𝐞𝐬𝐭𝐢𝐨𝐧𝐬

    What emerged from this follow-up inquiry highlights significant discrepancies between the statements published on the group’s blog and the technical characteristics of the data examined. Despite our additional questions, no verifiable evidence was provided to substantiate the claims. Instead, we were told that authenticity could be confirmed through the purchase of the stolen database — a proposal we firmly rejected.

    suspectfile.com/doubts-over-ba

    #APT73 #Bashe #CloudSEK #IndianBank #IndonesianBank #LineBank #Ransomware