September 2, 2026
- Attackers stole a METR API key and burned roughly $600,000 in AI model credits before anyone noticed — for weeks. The nonprofit that evaluates frontier models for long-horizon agentic capability disclosed two separate intrusion attempts (The Register, Dark Reading). Credential hygiene and spend alerting on model APIs is now a real attack surface, not a billing concern (earlier coverage). · AI & Model Security
in OpenAI Says Astra Crossed the Line: Autonomous Zero-Day Discovery at "Critical" Cyber Risk