Critical

Attackers Steal METR API Key and Consume AI Credits Worth About $600,000

The Hacker News
Actively Exploited

Overview

METR, a non-profit focused on evaluating artificial intelligence models, reported that attackers stole an API key and used it to consume AI credits worth approximately $600,000. The organization experienced two significant security incidents aimed at unauthorized access to its systems. Fortunately, METR stated that no sensitive information was compromised during these events. This incident not only impacts METR's financial resources but also raises concerns about the security of AI-related infrastructure, highlighting the vulnerabilities that organizations in this space may face. As AI technology continues to evolve, ensuring robust security measures is crucial to prevent similar incidents in the future.

Key Takeaways

  • Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
  • Affected Systems: METR API, AI credits
  • Action Required: Implement stronger access controls and monitor for unauthorized activity.
  • Timeline: Disclosed on [date not specified]

Original Article Summary

METR (short for Model Evaluation and Threat Research and pronounced "Meter"), a research non-profit that evaluates frontier artificial intelligence (AI) models for their ability to carry out long-horizon, agentic tasks, disclosed that it suffered "two notable security incidents" where external actors attempted to gain unauthorized access to its systems. No sensitive information is believed to

Impact

METR API, AI credits

Exploitation Status

This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.

Timeline

Disclosed on [date not specified]

Remediation

Implement stronger access controls and monitor for unauthorized activity.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Coverage

Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests

The Hacker News

The Iranian hacking group known as Nimbus Manticore has been linked to two new types of malware that can affect both Linux and macOS systems. These malware families are remote access trojans (RATs) created using Node.js and JavaScript, allowing attackers to gain control over infected devices. Researchers from Kaspersky noted that the group is using a clever tactic of posing as recruiters to deliver malicious code through fake coding tests. This development is concerning as it expands the group's targeting capabilities and indicates a shift in their methods. Users and organizations using Linux or macOS systems should be vigilant and consider enhancing their security measures to prevent potential infections.

Sep 1, 2026

Russia-Aligned UAC-0099 Plants Nuclear Weapon Prompt in Malware to Disrupt AI Analysis

The Hacker News

Researchers have identified a new technique called GuardBreaker, employed by a Russia-aligned hacker group known as UAC-0099. This group targeted an entity in Ukraine with the goal of disrupting artificial intelligence systems, specifically by triggering safety mechanisms in large language models (LLMs). By doing so, they aim to manipulate AI-assisted analysis, potentially leading to misinformation or faulty decision-making. This incident underscores the growing intersection of cybersecurity and AI, raising concerns about the effectiveness of AI technologies in secure environments. The implications could extend beyond Ukraine, affecting how organizations worldwide integrate AI into their operations.

Sep 1, 2026

Recently patched PaperCut zero-days used in data theft attacks

BleepingComputer

Two recently patched vulnerabilities in the PaperCut NG and MF print management software are now being exploited in data theft attacks. These flaws were initially discovered and addressed last week, but attackers have quickly adapted to use them for unauthorized access to sensitive data. Organizations that rely on PaperCut for managing printing services should be particularly vigilant, as these vulnerabilities could lead to serious data breaches if not properly mitigated. Users are urged to apply the latest security updates immediately to protect their systems from potential exploitation. This situation serves as a reminder of the importance of timely patch management in cybersecurity.

Sep 1, 2026

Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity

The Hacker News

Recent research by VulnCheck has revealed that attackers are exploiting two serious vulnerabilities in Langflow and Ruby on Rails. The first vulnerability, CVE-2026-0768, has a CVSS score of 9.8 and allows attackers to execute arbitrary Python code as the root user due to inadequate validation of user input. The second vulnerability, CVE-2026-66066, also poses a significant risk, although specific details were not provided in the report. These flaws could lead to unauthorized access and control over affected systems, making it crucial for organizations using these platforms to take immediate action. Companies and developers should prioritize patching these vulnerabilities to safeguard their applications and data.

Sep 1, 2026

PaperCut Exploitation Escalates to Active Intrusions

SecurityWeek

CISA has flagged two vulnerabilities in PaperCut, identified as CVE-2026-82078 and CVE-2026-81578, which are now being actively exploited. These vulnerabilities have the potential to allow attackers to gain unauthorized access to systems using PaperCut, a popular print management software used by organizations worldwide. This escalation of exploitation means that users of PaperCut should be particularly vigilant about securing their systems. The vulnerabilities were added to CISA's Known Exploited Vulnerabilities (KEV) catalog, signaling the urgency for organizations to take action. Companies relying on PaperCut need to assess their installations and apply any available security patches to mitigate the risk of intrusions.

Sep 1, 2026

Anthropic Users Hit by Infostealer Attacks, Session Thefts

darkreading

Users of Anthropic's AI platform, Claude, have fallen victim to infostealer attacks, which allowed attackers to gather session information and gain unauthorized access to their accounts. The exact number of affected users remains unclear, but the incident raises significant concerns about the security of user data on such platforms. Infostealers are malicious programs designed to extract sensitive information, and in this case, they specifically targeted user sessions, potentially compromising personal data and interactions. This incident serves as a reminder for users to be vigilant about their account security, especially when using online services that handle sensitive information.

Aug 31, 2026