Terabytes of credentials leaked in massive supply-chain attack
A supply-chain attack on an AI package compromised 2,500 users, resulting in the theft of terabytes of credentials.

- A supply-chain attack on an AI package compromised 2,500 user accounts, exposing terabytes of credentials.
- The breach highlights vulnerabilities in third-party AI tools and the risks of cascading security failures.
- Attackers scraped and exfiltrated credentials, raising concerns about data protection in AI ecosystems.
- Experts warn of increased supply-chain attacks as AI tools rely more on external dependencies.
Security researchers uncovered a significant supply-chain attack targeting an AI package, which led to the compromise of 2,500 user accounts. The attackers scraped and exfiltrated terabytes of credentials, raising concerns about the security of AI tools and the broader implications for data protection in the AI ecosystem. The incident highlights vulnerabilities in third-party dependencies and the potential for cascading effects when AI tools are compromised.
The breach underscores the importance of robust security practices in AI development and deployment. Experts warn that such attacks could become more common as AI tools increasingly rely on external packages and libraries. The compromised credentials could be used for further attacks, including phishing, identity theft, or unauthorized access to sensitive systems.
Developers must prioritize security in AI tool development and vet third-party dependencies rigorously.
Businesses using AI tools face heightened risks of credential theft and potential data breaches.
The incident raises awareness about the security risks of AI tools and the need for stronger protections.
- supply-chain attack
- A cyberattack that targets vulnerabilities in third-party software or services to compromise a primary system.
Wearables Powered by Artificial Intelligence: Latest Security Issue – RACmonitor - MedLearn Publishing
Intelligence Community CIOs Warn Autonomous AI Agents Are Reshaping Cyber Threat Landscape - ExecutiveGov
Marine Corps, Coast Guard Lay Groundwork for AI Operations - GovCIO Media & Research
SecurityResearchers found a way to hijack devices through Zoom screen sharing
AI, China, and the New Risks to U.S. Security: Q&A with Matan Chorev - RAND Corporation
BusinessTwitch content has trained Amazon AI for years, but users can opt out now
Twitch streams have been used to train Amazon's AI models for years, and the platform now offers creators an opt‑out option.

The White House Is Going to Expand Its AI Policy
The White House is preparing to expand its AI policy framework to include open models, according to sources cited by WIRED.
BusinessTrump sued over "brazen" scheme to sell Truth Social API access for $100K a month
A lawsuit accuses Trump of selling exclusive API access to Truth Social for $100,000 per month, prioritizing his own generated content.
Transparency, Safety Are Focuses for Illinois AI Laws - GovTech
Illinois has enacted new AI laws prioritizing transparency and safety, setting a precedent for state-level AI governance.
BusinessAmazon will train on Twitch streamers’ content by default, unless they opt out
Amazon will train its AI models on Twitch streamers' content by default, with an opt-out mechanism for creators.
Three Resources Consider Responsible Use of AI in College Access - NCAN
NCAN published three resources to guide responsible AI use in college access programs, aiming to ensure fairness and transparency.