From CI Pipeline to Ransomware & Breaches: 6 High-Profile Breaches in the LiteLLM/Trivy Attack

From CI Pipeline to Ransomware & Breaches: 6 High-Profile Breaches in the LiteLLM/Trivy Attack

Keypoints

  • The LiteLLM and Trivy campaign exposed secrets through compromised CI runner environments.
  • Hudson Rock completed more than 250 ethical disclosures to affected organizations worldwide.
  • Guesty and S&P Global had AWS keys, tokens, and other secrets used in downstream extortion.
  • Cisco and the European Commission were impacted through poisoned development and Terraform workflows.
  • Mercor and Telnyx suffered major fallout from leaked credentials and malicious package activity.

Read More: https://www.infostealers.com/article/from-ci-pipeline-to-ransomware-breaches-6-high-profile-breaches-in-the-litellm-trivy-attack/