Find notable cyber news and cases, enriched with sources, timelines, and signals.

METR hit by network compromise

Incident
First reported
Last updated
Happening score
H score 31
1 unique sources, 1 articles

Summary

Hide ▲

METR disclosed a March 2026 incident in which attackers stole an API key for public-model inference and consumed a substantial amount of credits, creating unauthorized usage and potential cost exposure. The compromise involved a publicly accessible EC2 instance whose authentication failed open, exposing the orchestration dashboard for days. METR said no sensitive information is believed to have been accessed, but the stolen credentials enabled three weeks of abuse that could have generated about $600,000 in charges.

Related Happenings

METR agent orchestration dashboard fail-open authentication security flaw

Vulnerability
H score32 First: 01.09.2026 12:05 Last: 01.09.2026 12:05 Sources 1

How related: the "vibe-coded app" suffered from a "fail-open vulnerability" that silently disabled authentication, causing the agent orchestration dashboard to be exposed to the public internet for several days.

About this happening: A fail-open authentication vulnerability in METR’s agent orchestration dashboard exposed the system to the public internet for several days, creating unauthorized-acce...

Hugging Face hit by network compromise

Incident
H score48 First: 27.08.2026 21:36 Last: 27.08.2026 21:36 Sources 1

About this happening: The Hugging Face breach expanded after attackers used a zero-day in HDF5 handling to extract credentials from production workers, increasing their access inside the en...

ReliaQuest hit by network compromise

Incident
H score37 First: 27.08.2026 18:12 Last: 27.08.2026 18:12 Sources 1

About this happening: ReliaQuest suffered a social-engineering incident on August 22, 2026 that gave an attacker a brief view-only session in its identity dashboard. The attacker used a...

Google hit by network compromise

Incident
H score42 First: 14.07.2026 09:19 Last: 14.07.2026 09:19 Sources 1

About this happening: Google confirmed a June 2025 compromise of one corporate Salesforce instance, and attackers took largely public business contact data before access was cut off. Th...

Timeline

  1. 01.09.2026 12:05 2 articles · 3h ago

    METR discloses stolen API key and sustained probing campaign

    Initial Disclosure

    METR disclosed that attackers stole an API key for inference on public models in March 2026 and consumed a substantial amount of credits, and that in May 2026 it observed a sustained external attack campaign that used credential stuffing, OAuth token grant attempts, service scanning, and phishing against publicly accessible infrastructure. METR said no sensitive information is believed to have been accessed, shared a version of its findings with AI companies it works with before public disclosure, and after the March compromise updated its security policies, monitoring, and spend alerts. METR also said it inadvertently exposed a read-only SQL query mechanism in its public transcript viewer and took the API offline after an independent security researcher reported the issue.

    Show sources