How to Format Your TDS Draft: A New and Improved Guide
Everything you need to know about creating a draft on our Contributor Portal
The post How to Format Your TDS Draft: A New and Improved Guide appeared first on Towards Data Science.
Everything you need to know about creating a draft on our Contributor Portal
The post How to Format Your TDS Draft: A New and Improved Guide appeared first on Towards Data Science.
Terabytes worth of credentials, many belonging to the worldβs biggest and most sensitive organizations, have been exposed in a supply-chain attack on LiteLLM, an open source tool that streamlines AI-driven software development. Microsoft, Amazon, Cisco, Samsung, and Salesforce are only a handful of the entities whose access secrets were exposed.
The revelation was posted on Tuesday and Wednesday by security firms CloudSEK and Hudson Rock. CloudSEK said it found cloud keys, repository tokens, SSH keys, Kubernetes secrets, package publishing credentials, environment variables, and AI provider keys that could allow attackers to gain access to more than 2,500 organizations.
The credentials were extracted during a 40-minute window in March while the victims used compromised versions of LiteLLM downloaded from the packageβs official location in the Python Package Index repository. Hudson Rock said it made the discovery after analyzing a 195TB file that it obtained. Neither firm identified the source of the information.


Β© Getty Images
Last week, a researcher outlined what he said was a βnovel attack surfaceβ in passkeys, the new authentication paradigm that offers a more secure alternative to password-based methods. In fact, the attacks demonstrated in the post are neither novel nor unique to passkeys. This distinction is important because the research has generated confusion among end users and security professionals as they assess whether this new mechanism is truly safe to use.
The attack is called Pass-ta-keyβa blending of the word passkey with the phrase βpass the keyβ and a nod to a plate of pasta. Arie Olshtein, a researcher at security firm Palo Alto Networks, described in a post last week how Pass-ta-key could obtain all passkeys stored in the Google Password Manager app (GPM) for Windows when itβs running on a machine infected with malware.
This came as a surprise to many people because they believed passkeys are stored exclusively in the trusted platform manager (TPM), the locked-down enclave in a hardened silicon chip thatβs reserved for storing cryptographic keys and other highly sensitive information on Windows machines. If passkeys are stored in the TPM, then how was Pass-ta-key able to extract the entire set of passkeys stored by the app, they wanted to know.


Β© Aurich Lawson | Getty Images