AI evaluation startup Braintrust confirms breach, tells every customer to rotate sensitive keys

AI evaluation platform Braintrust suffered a breach of its AWS cloud account containing customer API keys, requiring all customers to immediately rotate their credentials to prevent unauthorized access to their AI infrastructure and data. This incident highlights the critical supply chain risk posed by third-party cloud service providers and underscores the need for IT organizations to implement zero-trust principles, credential management policies, and rapid incident response procedures for vendor security incidents. The breach demonstrates that even well-funded AI infrastructure providers ($800M valuation) are vulnerable to cloud misconfiguration attacks, with potential downstream impacts across dependent AI applications and customer systems.

Lorenzo Franceschi-BicchieraiTechCrunch2 min read
Read full article
AI evaluation startup Braintrust confirms breach, tells every customer to rotate sensitive keys
Braintrust, a startup that makes an “operating system for engineers building AI software,” notified customers that hackers broke into one of its Amazon cloud environments, and is asking customers to rotate their API keys.