METR agent orchestration dashboard fail-open authentication security flaw
Vulnerability
Summary
Hide ▲
Show ▼
A fail-open authentication vulnerability in METR’s agent orchestration dashboard exposed the system to the public internet for several days, creating unauthorized-access risk. The dashboard was meant to sit behind Google authentication, but the flaw silently disabled that control. METR said no sensitive information is believed to have been accessed, but the exposure left a public-facing management surface reachable by outsiders.
Related Happenings
METR hit by network compromise
Incident
H score31
First: 01.09.2026 12:05
Last: 01.09.2026 12:05
Sources 1
How related:
In March 2026, attackers stole an API key for inference on public models and consumed a substantial amount of credits," METR said.
About this happening:
METR disclosed a March 2026 incident in which attackers stole an API key for public-model inference and consumed a substantial amount of credits, creating unauthorized...
METR hit by network compromise
IncidentHow related: In March 2026, attackers stole an API key for inference on public models and consumed a substantial amount of credits," METR said.
About this happening: METR disclosed a March 2026 incident in which attackers stole an API key for public-model inference and consumed a substantial amount of credits, creating unauthorized...
Artifactory token-refresh via legacy credential endpoint security flaw
Vulnerability
H score44
First: 27.08.2026 21:36
Last: 27.08.2026 21:36
Sources 1
About this happening:
Artifactory's token-refresh vulnerability in a legacy credential endpoint was exploited on June 26 2026, giving agents administrator-level access and raising takeo...
Artifactory token-refresh via legacy credential endpoint security flaw
VulnerabilityAbout this happening: Artifactory's token-refresh vulnerability in a legacy credential endpoint was exploited on June 26 2026, giving agents administrator-level access and raising takeo...
ReliaQuest hit by network compromise
Incident
H score37
First: 27.08.2026 18:12
Last: 27.08.2026 18:12
Sources 1
About this happening:
ReliaQuest suffered a social-engineering incident on August 22, 2026 that gave an attacker a brief view-only session in its identity dashboard. The attacker used a...
ReliaQuest hit by network compromise
IncidentAbout this happening: ReliaQuest suffered a social-engineering incident on August 22, 2026 that gave an attacker a brief view-only session in its identity dashboard. The attacker used a...
Open-source admin tool zero-day 2FA bypass exploitation wave
Exploitation Wave
H score6
First: 11.05.2026 18:45
Last: 11.05.2026 18:45
Sources 1
About this happening:
Google identified a mass vulnerability exploitation operation using a zero-day 2FA bypass against a popular open-source, web-based system administration tool, creating...
Open-source admin tool zero-day 2FA bypass exploitation wave
Exploitation WaveAbout this happening: Google identified a mass vulnerability exploitation operation using a zero-day 2FA bypass against a popular open-source, web-based system administration tool, creating...
Timeline
-
01.09.2026 12:05 2 articles · 3h ago
METR agent orchestration dashboard exposed by fail-open authentication flaw
Initial DisclosureA fail-open vulnerability silently disabled Google authentication on METR’s agent orchestration dashboard, exposing the dashboard to the public internet for several days in March 2026. METR said no sensitive information is believed to have been accessed.
Show sources
- Attackers Steal METR API Key and Consume AI Credits Worth About $600,000 — thehackernews.com — 01.09.2026 12:05
- Attackers Steal METR API Key and Consume AI Credits Worth About $600,000 — thehackernews.com — 01.09.2026 12:05