Keypoints
- The LiteLLM and Trivy campaign exposed secrets through compromised CI runner environments.
- Hudson Rock completed more than 250 ethical disclosures to affected organizations worldwide.
- Guesty and S&P Global had AWS keys, tokens, and other secrets used in downstream extortion.
- Cisco and the European Commission were impacted through poisoned development and Terraform workflows.
- Mercor and Telnyx suffered major fallout from leaked credentials and malicious package activity.