Normal view
-
Robotics & Automation News
- VUB leads European project teaching soft robots to sense, repair and adapt
-
Robotics & Automation News
- Interview with Lattice Semiconductor’s Karl Wachswender: ‘Parallel processing enables more powerful edge AI’
Interview with Lattice Semiconductor’s Karl Wachswender: ‘Parallel processing enables more powerful edge AI’
-
Robotics & Automation News
- Northrop Grumman launches robotic spacecraft to repair and extend life of satellites
Northrop Grumman launches robotic spacecraft to repair and extend life of satellites
-
Robotics & Automation News
- Honda’s new ‘Avatar’ humanoid robot suggests the spirit of ASIMO is very much alive
Honda’s new ‘Avatar’ humanoid robot suggests the spirit of ASIMO is very much alive
Terabytes of credentials leaked in massive supply-chain attack
Terabytes worth of credentials, many belonging to the world’s biggest and most sensitive organizations, have been exposed in a supply-chain attack on LiteLLM, an open source tool that streamlines AI-driven software development. Microsoft, Amazon, Cisco, Samsung, and Salesforce are only a handful of the entities whose access secrets were exposed.
The revelation was posted on Tuesday and Wednesday by security firms CloudSEK and Hudson Rock. CloudSEK said it found cloud keys, repository tokens, SSH keys, Kubernetes secrets, package publishing credentials, environment variables, and AI provider keys that could allow attackers to gain access to more than 2,500 organizations.
40 minutes is all it takes
The credentials were extracted during a 40-minute window in March while the victims used compromised versions of LiteLLM downloaded from the package’s official location in the Python Package Index repository. Hudson Rock said it made the discovery after analyzing a 195TB file that it obtained. Neither firm identified the source of the information.


© Getty Images
New Pass-ta-key attack reveals all the things we didn't know about passkeys
Last week, a researcher outlined what he said was a “novel attack surface” in passkeys, the new authentication paradigm that offers a more secure alternative to password-based methods. In fact, the attacks demonstrated in the post are neither novel nor unique to passkeys. This distinction is important because the research has generated confusion among end users and security professionals as they assess whether this new mechanism is truly safe to use.
The attack is called Pass-ta-key—a blending of the word passkey with the phrase “pass the key” and a nod to a plate of pasta. Arie Olshtein, a researcher at security firm Palo Alto Networks, described in a post last week how Pass-ta-key could obtain all passkeys stored in the Google Password Manager app (GPM) for Windows when it’s running on a machine infected with malware.
This came as a surprise to many people because they believed passkeys are stored exclusively in the trusted platform manager (TPM), the locked-down enclave in a hardened silicon chip that’s reserved for storing cryptographic keys and other highly sensitive information on Windows machines. If passkeys are stored in the TPM, then how was Pass-ta-key able to extract the entire set of passkeys stored by the app, they wanted to know.


© Aurich Lawson | Getty Images
-
Robotics & Automation News
- Interview with the IEEE’s Dejan Milojicic: 30 technology megatrends for 2030
Interview with the IEEE’s Dejan Milojicic: 30 technology megatrends for 2030
-
Robotics & Automation News
- Interview with Maximo’s Nick Hegeman: 180,000 robotic installations of solar panels and counting
Interview with Maximo’s Nick Hegeman: 180,000 robotic installations of solar panels and counting
-
Robotics & Automation News
- Interview with Icarus Robotics co-founder Jamie Palmer: Building a ‘robotic labor force for space’
Interview with Icarus Robotics co-founder Jamie Palmer: Building a ‘robotic labor force for space’
-
Robotics & Automation News
- Cold calling: How autonomous robots are transforming polar science in the Arctic and Antarctic
Cold calling: How autonomous robots are transforming polar science in the Arctic and Antarctic
-
Robotics & Automation News
- Researchers develop control system that helps bird-inspired robots stay stable in windy conditions
Researchers develop control system that helps bird-inspired robots stay stable in windy conditions
-
Robotics & Automation News
- Interview with Arduino’s Marcello Majonchi: Qualcomm acquisition ushers in new era of edge AI and robotics
Interview with Arduino’s Marcello Majonchi: Qualcomm acquisition ushers in new era of edge AI and robotics
Trends and outlook for actuators: The muscles behind humanoid motion
How to choose a massage chair
-
Robotics & Automation News
- Case study: Hai Robotics helps LPP Logistics scale automated e-commerce fulfilment in Romania
Case study: Hai Robotics helps LPP Logistics scale automated e-commerce fulfilment in Romania
America hits Chinese humanoids where it hurts
-
Robotics & Automation News
- Why the United States’ FCC now considers advanced robots a national security risk
Why the United States’ FCC now considers advanced robots a national security risk
-
Robotics & Automation News
- When robots start to feel: HBK and Siléane bring tactile intelligence to high-speed cosmetics packaging
When robots start to feel: HBK and Siléane bring tactile intelligence to high-speed cosmetics packaging
Orico MiniRaid review: A different kind of external storage
Hackers can use 9 of the most popular AI tools to assemble massive botnets
In the brief history of AI security, the prompt injection has quickly become the top threat. Large language models are inherently unable to distinguish between legitimate instructions provided by users and malicious ones sneaked into emails, source code, and other third-party content the models are processing. This makes it trivial to surreptitiously inject malicious commands that the LLM readily follows.
With no way to enforce this crucial boundary between trusted and untrusted sources, AI engine developers are left to erect elaborate guardrails designed to mitigate the damage rather than solve the root cause.
To date, most prompt injections have fallen into a class known as push, in which each potential victim is targeted. For example, the adversary injects malicious instructions into an individual email or calendar invitation. Because the injection must then be sent (or pushed) to each specific target, the scale of the attack is limited, hampering mass exploits that hit the Internet at large.

