AI Firm Braintrust Prompts API Key Rotation After Data Breach
AI evaluation and observability platform Braintrust urged customers this week to rotate API keys that may have been compromised after hackers accessed an AWS account.
The incident, the company says, was discovered on May 4, after receiving a report of suspicious behavior, and was communicated to customers via email on May 5. The message also included indicators of compromise (IOCs) and remediation steps.
Immediately after learning of the incident, Braintrust locked down the compromised account, audited related systems and restricted access to them, rotated internal secrets, and launched an investigation into the matter.
The internal AWS account used by its systems, Braintrust says, likely provided the attackers with access to API keys that organizations use to access AI models.
“As a precaution, we recommend that all customers rotate any org-level AI provider keys used with Braintrust,” the company said in an incident notice.
According to the company, at least...
Copyright of this story solely belongs to securityweek.com. To see the full text click HERE