// AWSHIGH
A 153GB archive of stolen credentials from the LiteLLM AI framework breach exposed access credentials for 2,488 corporate domains, including AWS, Samsung, and Cisco. The compromised credentials originated from a breach of the LiteLLM open-source AI framework and were publicly surfaced in August 2026. Organizations using AWS should audit access logs and rotate exposed credentials.
- ServiceNow, Microsoft, Salesforce, Cisco, LiteLLM, GitHub and AW(opens in a new tab)
- From CI Pipeline to Ransomware & Breaches: 6 High-Profile Breach(opens in a new tab)
- Massive supply-chain attack sees terabytes of data belonging to (opens in a new tab)
// Get alerts for AWS