A massive 153GB archive stolen during the LiteLLM supply chain attack exposes credentials and other sensitive data linked to thousands of corporate domains, including AWS, Samsung, Cisco, and Salesforce. Hudson Rock says it obtained and analyzed the archive, which contains 433,909 files, and attributed 118,829 CI runner dumps to 2,488 corporate domains. “We are leveraging this data for a global et

A substantial archive of 153GB containing credentials and other sensitive information, reportedly stolen during a supply chain attack involving the open-source proxy gateway LiteLLM, has surfaced. The data is linked to thousands of corporate domains, including major entities like AWS, Samsung, Cisco, and Salesforce.
Hudson Rock, a cybersecurity firm, claims to have obtained and analyzed the archive, which comprises 433,909 files. Their analysis attributes 118,829 CI runner dumps to 2,488 distinct corporate domains. The firm has initiated a global ethical disclosure effort to assist organizations in proactively responding to the exposure before the data is potentially weaponized by threat actors.
LiteLLM, an open-source proxy gateway utilized by developers to route requests to various AI models, was compromised following an earlier breach of Trivy, a widely used open-source vulnerability scanner. On March 19, 2026, the cybercriminal group TeamPCP, which emerged in late 2025, allegedly used stolen credentials to publish a malicious version of Trivy.
LiteLLM's build pipeline automatically installed Trivy, granting the poisoned scanner read access to the runner environment. This access allowed the attackers to steal LiteLLM's PyPI publishing tokens. Leveraging these tokens, TeamPCP subsequently published two malicious LiteLLM releases, versions 1.82.7 and 1.82.8, to the Python Package Index on March 24.
The exposed dataset includes information tied to organizations such as NVIDIA, Volkswagen, Microsoft, FedEx, S&P Global, John Deere, Epic Games, Orange, TomTom, BT Group, ServiceNow, Deloitte, and Siemens. Screenshots accompanying the research reportedly show AWS secret access keys, Salesforce client secrets, Slack signing secrets, Azure environment variables, and AI provider API keys captured during pipeline execution.
Another cybersecurity firm, CloudSEK, working with a separate dataset of approximately 434,000 stolen files, estimates the number of exposed organizations to be close to 2,500. CloudSEK emphasizes that these figures represent potential exposure rather than confirmed breaches.
Identifying the specific owners of the exposed secrets presents a challenge. Hudson Rock notes that accurate attribution requires analyzing infrastructure boundaries beyond surface-level indicators. For instance, a leaked pipeline might be linked to a committer email at one company, but infrastructure markers in the same data dump could point to a subsidiary. A significant portion of the dumped files lack clear ownership, containing database passwords, third-party API keys, and cloud credentials without identifying company email addresses, custom domains, or internal server names. This means some organizations may have exposed credentials without being aware of their compromise.
Hudson Rock is urging organizations that use AI proxy infrastructure, third-party CI/CD vulnerability scanners, or downstream AI packages to audit their environments for LiteLLM versions 1.82.7 and 1.82.8. Any secrets accessible to the LiteLLM environment should be considered compromised. Recommended actions include rotating cloud IAM keys and access tokens, reviewing audit logs for anomalous activity dating back to March 24, and checking for unauthorized .pth files and suspicious systemd services.
Despite the scale of the exposure, some organizations reportedly appear to be addressing the findings with less urgency than warranted. One major US tech company, for example, claimed to have rotated all affected credentials, yet subsequent testing by a security researcher found many of them still active.
Hudson Rock states that the data is not currently circulating widely, presenting a critical window of opportunity for companies to rotate keys and secrets before a wider leak occurs. The firm emphasizes that the magnitude of this incident necessitates a new level of response from the cybersecurity industry.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed