
01
Terabytes of credentials leaked in massive supply-chain attack
The gist: A supply-chain attack on LiteLLM exposed terabytes of sensitive credentials from more than 2,500 organizations, including major technology and financial companies.
Big pictureThe incident shows how one hacked software package can spread risk through the tools companies use to build and deliver their own software. The danger is not limited to AI itself: weak security around software supply chains and development systems can turn a short attack into a much larger breach.
Explain like I'm 5Some trusted software was secretly changed so it copied passwords and access keys from computers using it. It was like a delivery box that quietly took valuables from thousands of homes before carrying them away.
Why it matters nowSecurity firms disclosed the stolen data on Tuesday and Wednesday after analyzing a 195-terabyte file, and they are urging affected organizations to revoke and replace exposed credentials. Organizations are being told to check specifically for LiteLLM versions 1.82.7 and 1.82.8.
Three things to know01The theft lasted 40 minutes
During that window in March, compromised LiteLLM versions read computer memory and sent its contents through an attacker-controlled channel.
02CI/CD systems were heavily exposed
Researchers said credentials from about 434,000 software pipelines were included, covering cloud keys, database passwords, repository tokens, and Kubernetes secrets.
03Some victims are hard to identify
Many stolen secrets lacked company names or domains, so researchers could not reliably connect every credential to its owner and warned that organizations may not know they are affected.
Trusted source
Ars Technica ↗

02
Researchers found a way to hijack devices through Zoom screen sharing
The gist: A flaw in Zoom’s screen-sharing system could let attackers silently take over devices, and AI found the working attack in fewer than 20 prompts.
Big pictureThe discovery shows how AI can make sophisticated software attacks faster and easier for people with fewer security skills. It also highlights the risks in trusted tools whose complicated, less-visible features may not receive enough public scrutiny.
Explain like I'm 5Imagine sharing a drawing board during a video call, but someone secretly uses a hidden mistake in that board to get into your computer. You would not need to click anything or notice anything for the attack to work.
Why it matters nowResearchers disclosed the Zoom flaws on Tuesday, and Zoom says it has already begun rolling out fixes. The vulnerabilities affected Zoom on Windows, macOS, Linux, iOS, and Android.
Three things to know01The bug hid in annotations
The vulnerable code handled real-time annotations during screen sharing, a specialized feature researchers targeted because complex and obscure components can contain overlooked mistakes.
02AI shortened the process
A Security said the same kind of discovery might previously have required five people and about six months of refining and testing.
03Every supported system was affected
The advisory covered all operating systems supported by Zoom, rather than limiting the problem to a single type of computer or phone.
Trusted source
Ars Technica ↗

03
Twitch content has trained Amazon AI for years, but users can opt out now
The gist: Twitch users were automatically opted into Amazon’s AI training, but they can now opt out of having their channel content used.
Big pictureThe change gives Twitch creators more control over how their work is used, while highlighting that online content can be repurposed for AI training without a separate request each time. It also shows how platform privacy choices may cover many kinds of content, not just livestreams.
Explain like I'm 5For years, Amazon could use things from Twitch channels to help teach its AI, like using ingredients to improve a recipe. Now creators can tell Twitch not to use their content for future training.
Why it matters nowTwitch announced the opt-out option today and added it to the account security settings. Users who do not want future training use must change the setting themselves.
Three things to know01The opt-out covers more than streams
It includes video-on-demand recordings, clips, stream chats, and the pictures and text on a channel.
02Training can improve captions
Twitch says a creator’s audio could help refine speech-to-text systems, improving captions on Twitch and elsewhere across Amazon.
03The setting targets future training
The support page describes the choice as preventing content from being used in future improvements to Amazon’s generative AI models.
Trusted source
Ars Technica ↗