Attackers used a stolen METR API key for three weeks, consuming model credits worth $600,000

The AI safety research organization METR has disclosed two separate security incidents, one in March and another in May, neither of which resulted in evidence of sensitive information access. The more significant event involved attackers stealing an API key and using it for three weeks to consume approximately $600,000 worth of AI model credits, which had been provided free of charge by an unnamed model developer.
The March incident began when a METR researcher operated agents on a personal Amazon EC2 instance that was publicly accessible and secured by Google authentication. This application, described as "vibe-coded," contained an API key for METR's public models account. A "fail-open" flaw in the authentication mechanism silently disabled it for several days, leaving the system exposed. METR suspects the attackers located the instance by analyzing certificate transparency lists for recently registered sites containing terms related to language models and agents.
Once access was gained, the attackers prompted an agent to reveal the model provider API key and established persistence by adding an SSH key. They then utilized these stolen credentials to generate a high volume of model traffic over three weeks. This illicit activity was difficult to distinguish from legitimate evaluation work, as METR researchers routinely generate significant model traffic, and there was no spending cap on free-credit keys. In response, METR revoked the researcher's access, rotated credentials, wiped the affected laptop, and notified the model developer. The organization has since implemented spend alerts for keys where feasible.
In a separate incident in early May, METR received a tip-off about financially motivated attackers targeting its public infrastructure, potentially seeking access to frontier models. These attackers extensively used agents to automate vulnerability discovery, including credential stuffing, attempts to grant OAuth tokens, scanning new services, and phishing attempts against staff.
During this period, METR also inadvertently exposed a read-only SQL query mechanism through its public transcript viewer. A bug in this mechanism could have allowed access to unpublished evaluation data, and the database itself had been accidentally loaded with sensitive model data it was not intended to hold. An independent researcher discovered and disclosed this flaw, prompting METR to take the interface offline and issue a bounty. METR confirmed that while the attackers probed this endpoint, there was no indication they discovered or exploited the bug.
METR has since implemented architectural separation, running public-facing applications in an environment distinct from its internal infrastructure. The organization stated its broader security measures were accurate as of July 30.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.

Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets