LIVE · cybersecurity feed
Live wire
CVE-2026-0768 · Critical Langflow flaw exploited to steal OpenAI and AWS keysCVE-2026-82329 · Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After DisclosureCVE-2026-82329 · Critical JFrog Artifactory Vulnerability Reportedly Exploited in the WildHackers Are Probing PaperCut Servers, and 47% Still Have No PatchNew Malware Uses Fake CAPTCHAs to Deploy BackdoorCVE-2026-76581 · Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCECVE-2026-76639 · Hack One Robot, Reach the Next: Unitree G1 Security FlawsRhysida Ransomware Group Targets Berlin Government Ahead of VoteThe Cybersecurity Apocalypse Is Coming in ‘Months,’ AI Giants WarnCVE-2023-49105 · Philippine Nuclear and Naval Targets Hit by Suspected Chinese Operator
ai

Attackers Steal METR API Key and Burn $600,000 in AI Credits

Attackers used a stolen METR API key for three weeks, consuming model credits worth $600,000

zeroday.news ·

The AI safety research organization METR has disclosed two separate security incidents, one in March and another in May, neither of which resulted in evidence of sensitive information access. The more significant event involved attackers stealing an API key and using it for three weeks to consume approximately $600,000 worth of AI model credits, which had been provided free of charge by an unnamed model developer.

The March incident began when a METR researcher operated agents on a personal Amazon EC2 instance that was publicly accessible and secured by Google authentication. This application, described as "vibe-coded," contained an API key for METR's public models account. A "fail-open" flaw in the authentication mechanism silently disabled it for several days, leaving the system exposed. METR suspects the attackers located the instance by analyzing certificate transparency lists for recently registered sites containing terms related to language models and agents.

Once access was gained, the attackers prompted an agent to reveal the model provider API key and established persistence by adding an SSH key. They then utilized these stolen credentials to generate a high volume of model traffic over three weeks. This illicit activity was difficult to distinguish from legitimate evaluation work, as METR researchers routinely generate significant model traffic, and there was no spending cap on free-credit keys. In response, METR revoked the researcher's access, rotated credentials, wiped the affected laptop, and notified the model developer. The organization has since implemented spend alerts for keys where feasible.

In a separate incident in early May, METR received a tip-off about financially motivated attackers targeting its public infrastructure, potentially seeking access to frontier models. These attackers extensively used agents to automate vulnerability discovery, including credential stuffing, attempts to grant OAuth tokens, scanning new services, and phishing attempts against staff.

During this period, METR also inadvertently exposed a read-only SQL query mechanism through its public transcript viewer. A bug in this mechanism could have allowed access to unpublished evaluation data, and the database itself had been accidentally loaded with sensitive model data it was not intended to hold. An independent researcher discovered and disclosed this flaw, prompting METR to take the interface offline and issue a bounty. METR confirmed that while the attackers probed this endpoint, there was no indication they discovered or exploited the bug.

METR has since implemented architectural separation, running public-facing applications in an environment distinct from its internal infrastructure. The organization stated its broader security measures were accurate as of July 30.

ai
ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI

ai

[Virtual Event] Building a Secure AI Strategy for the Enterprise

patch

The Collective Cyber Defense letter wrote your next vendor questionnaire

More than 200 companies have now signed to an August 27 letter about improving cyber defenses in the age of AI. Buried in it are three metrics every one of them endorse under its own logo: coverage, containment speed, and whether fixes work. The post The Collective Cyber Defense letter wrote your next vendor questionnaire appeared first on CyberScoop.

ai

Rewiring Democracy Series on The Renovator

Nathan E. Sanders and I are writing a series of essays on real-world examples of democratic technologies for The Renovator. I haven’t been posting the full text on the blog because they’re a bit long, but here are links. Part 1 is about the Japanese digital democracy party, Team Mirai. Part 2 is about the Swiss Public AI model, Apertus. Part 3 is about the civic technologists of Open Knowledge Bra

patch

Hackers push malicious Virtualizor update in BGP hijacking attack

Hackers delivered malicious updates to the Virtualizor VPS management software after hijacking BGP routing for its update infrastructure and redirecting update requests to malicious servers. [...]

breach

Novocure data breach affects more than 1,400 cancer patients

Healthtech company Novocure says the data of an undisclosed number of employees and more than 1,400 U.S. cancer patients has been exposed in a mid-August cyberattack. [...]