LiteLLM のサプライチェーン攻撃でテラバイト級の認証情報が漏洩
本文の状態
日本語全文を表示中
詳細モードで約1分の本文を読めます。
同じ出来事の情報源
この情報源を基点に整理
Ars Technica AI
セキュリティ調査会社 CloudSEK と Hudson Rock が、AI 開発支援ツール LiteLLM のサプライチェーン攻撃により、マイクロソフトやアマゾンなど 2,500 以上の組織の認証情報が漏洩したと発表した。
Continue in AI NEW LAB
このニュースを、実務の判断につなげる
AI NEW LABで、試したことや先に確認したい条件を共有できます。まずはログインなしで読めます。
AI NEW LABで論点を見るAI深層分析を開く2026年8月13日 06:56
AI深層分析
キーポイント
大規模な認証情報漏洩の実態
Microsoft、Amazon、Cisco、Samsung、Salesforce など世界有数の組織を含む 2,500 以上のエンティティのアクセスシークレットが暴露された。
攻撃経路と手法
Python Package Index からダウンロードした改ざんされた LiteLLM のバージョンを使用している間に、40 分間の窓で認証情報が抽出された。
漏洩情報の多様性
クラウドキー、リポジトリトークン、SSH キー、Kubernetes シークレット、パッケージ公開資格情報、環境変数、AI プロバイダーキーなど多岐にわたる機密情報が含まれる。
調査機関の発見経緯
CloudSEK と Hudson Rock が 195TB のファイルを分析してこの事象を発見したが、情報の流出元を特定することはできなかった。
重要な引用
Terabytes worth of credentials, many belonging to the world's biggest and most sensitive organizations, have been exposed in a supply-chain attack on LiteLLM
The credentials were extracted during a 40-minute window in March while the victims used compromised versions of LiteLLM downloaded from the package's official location in the Python Package Index repository.
編集コメントを表示
編集コメント
AI ツールの普及に伴い、開発ツール自体が攻撃の標的となるリスクが顕在化している。企業は単にツールの機能だけでなく、その供給経路の信頼性についても継続的な監視を怠ってはいけない。
Source Article
元記事を日本語で読む
本文に関係しない購読案内、埋め込み通知、サイト内プロモーションは除いています。
AI駆動型ソフトウェア開発を効率化するオープンソースツール「LiteLLM」に対するサプライチェーン攻撃により、世界有数の大規模かつ機密性の高い組織に属する多数の認証情報が露見しました。Microsoft、Amazon、Cisco、Samsung、Salesforceなど、アクセスシークレットが流出した組織は数多く存在します。
この事実は火曜日から水曜日にかけて、セキュリティ企業CloudSEKとHudson Rockによって発表されました。CloudSEKによると、クラウドキー、リポジトリトークン、SSH鍵、Kubernetesのシークレット、パッケージ公開認証情報、環境変数、AIプロバイダーキーなどが発見され、これらを利用すれば攻撃者が2,500以上の組織に侵入できる可能性があります。
40分あれば十分です
これらの認証情報は、3月に発生した40分間の窓期間中に抽出されました。当時、被害者はPython Package Indexリポジトリの公式場所からダウンロードした、侵害されたバージョンのLiteLLMを使用していました。Hudson Rockは、入手した195TBのファイルを分析した結果、この事実を発見しました。両社とも情報の流出元については特定していません。
記事全文を読む
コメント
原文を表示
Terabytes worth of credentials, many belonging to the world’s biggest and most sensitive organizations, have been exposed in a supply-chain attack on LiteLLM, an open source tool that streamlines AI-driven software development. Microsoft, Amazon, Cisco, Samsung, and Salesforce are only a handful of the entities whose access secrets were exposed.
The revelation was posted on Tuesday and Wednesday by security firms CloudSEK and Hudson Rock. CloudSEK said it found cloud keys, repository tokens, SSH keys, Kubernetes secrets, package publishing credentials, environment variables, and AI provider keys that could allow attackers to gain access to more than 2,500 organizations.
40 minutes is all it takes
The credentials were extracted during a 40-minute window in March while the victims used compromised versions of LiteLLM downloaded from the package’s official location in the Python Package Index repository. Hudson Rock said it made the discovery after analyzing a 195TB file that it obtained. Neither firm identified the source of the information.
Read full article
Comments
今日のまとめ
AIデイリーブリーフで今日の重要ニュースをまとめ読み