Stolen AI API Key Leaves One Company With Nearly $1 Million Bill
Unit 42 says stolen AI API keys can reach gray-market proxy services within minutes, turning one exposed credential into catastrophic usage charges.
Read article →Reader view
Choose the default article length.
Authentication, access, credentials, and identity systems.
Unit 42 says stolen AI API keys can reach gray-market proxy services within minutes, turning one exposed credential into catastrophic usage charges.
Read article →Public research turns a patched NetScaler memory overflow into a root-code-execution risk for SAML deployments, making build verification urgent.
Read article →Customer contact data is public after a social-engineering breach; defenders should harden support and identity checks against targeted impersonation.
Read article →Rapid7 joined a SharePoint identity bypass to unsafe .NET type creation. August's cumulative updates complete Microsoft's two-cycle fix.
Read article →Government agencies traced Gunra from exploited edge devices through credential theft, cloud exfiltration, backup deletion, and cross-platform ransomware.
Read article →Remus uses an Ethereum smart contract to resolve changing command infrastructure before stealing browser sessions, credentials, and wallet data.
Read article →Code in a signed-in Windows session can invoke a TPM-backed Windows Hello for Business key, authenticate without a device identity claim, and create a path to durable Entra access.
Read article →SpecterOps shows how relayed WSUS machine-account access can forge targeted updates and bypass payload signature checks when SUSDB runs on a separate SQL Server.
Read article →Unit 42 showed three post-compromise paths from Chrome's local passkey state to silent assertions, substituted verification keys, or the master secret protecting synced credentials.
Read article →N-central operators need Hotfix 2 build 2026.3.1.10 and a downstream endpoint hunt because the new release supersedes the first hotfix.
Read article →A crafted AD CS chase sent the CA to rogue directory services. July updates add a real-DC check, but defenders still need issuance and replication evidence.
Read article →Talos tied QR-code PDFs to credential theft, inbox-rule changes, SharePoint staging and new phishing sent from compromised Microsoft 365 mailboxes.
Read article →Zenity found URL parameters that preselected a template and auto-submitted instructions inside a logged-in user's Workspace Agents builder.
Read article →