Stolen AI API Key Leaves One Company With Nearly $1 Million Bill
Unit 42 says stolen AI API keys can reach gray-market proxy services within minutes, turning one exposed credential into catastrophic usage charges.
Read article →Reader view
Choose the default article length.
Cloud platforms, SaaS, containers, and infrastructure.
Unit 42 says stolen AI API keys can reach gray-market proxy services within minutes, turning one exposed credential into catastrophic usage charges.
Read article →Customer contact data is public after a social-engineering breach; defenders should harden support and identity checks against targeted impersonation.
Read article →A remote SCTP peer can trigger the kernel flaw, while Tencent separately demonstrated local privilege escalation and container escape. Defenders need both reachability and running-kernel checks.
Read article →Langflow, N-central, and Tomcat flaws entered CISA's exploited catalog. One gives unauthenticated callers Python execution by default.
Read article →A crafted image can reach unsafe libvips operations through Active Storage, exposing files and process credentials that a Rails-only update cannot recover.
Read article →Hugging Face traced 17,600 actions from an Artifactory escape through two malicious-dataset vectors and into its clusters, network and source control.
Read article →Any authenticated proxy-key holder could make two MCP preview endpoints run an arbitrary command on the LiteLLM host.
Read article →CVE-2026-6875 chained query evaluation with a sandbox escape, giving an unauthenticated attacker broad control of a ServiceNow instance and its connected proxy servers.
Read article →CVE-2025-55241 allowed an Entra actor token from one tenant to impersonate users in another through the legacy Azure AD Graph API.
Read article →CVE-2026-12957 allowed project configuration to start MCP processes with a developer's environment. AWS fixed the flaw in Language Servers for AWS 1.65.0.
Read article →A forgotten Klue credential led to customer OAuth token theft and direct access to Salesforce CRM data across several companies.
Read article →The botnet gives AI workbenches priority in its scan queue, then searches compromised hosts for cloud credentials, service-account tokens, and callable tools.
Read article →