Attackers Steal METR API Key and Burn $600,000 in AI Credits

2026-09-01T14:52:08Z31d5770b3ffbdf89e7a25129fb28b332714d404c0fd900918292029a978ae629
active-exploitationagentic-aiai-securityandroid-malwareapi-key-abuseaviation-securitycloud-securitycredential-theftcritical-infrastructurecybersecurity-newsdata-breachddosfinancial-sectorhealthcare-securityics-securitykevmacos-malwaremalwarenation-statephishingransomwaresocial-engineeringsupply-chain-securitythreat-actorsvulnerability-management

What happened

A curated security-news feed covering major incidents, active exploitation, phishing and malware campaigns, threat actors targeting critical infrastructure, AI-agent security risks, data breaches, supply-chain compromises, and defensive guidance. Notable items include stolen AI API credentials causing substantial cloud-credit abuse, widespread SVG phishing, ransomware operators using AI coding agents, active exploitation of TeamCity and other KEV-listed flaws, attacks affecting healthcare, aviation, utilities and government services, leaked AWS keys, and emerging agentic-AI and multi-cloud##.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
infosecurity_magazine
Record identifier
31d5770b3ffbdf89e7a25129fb28b332714d404c0fd900918292029a978ae629
Enrichment time
2026-09-01T14:52:08Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.