Attackers are hammering internet-facing Vite development servers to pull AWS and Azure credentials and infrastructure state files.
Thousands of exposed AI gateways accept the demo key printed in LiteLLM's setup guide.
CrowdStrike details Slim Spider, a Brazil-based group stealing crypto custody secrets from financial clouds.
JetBrains tells Cadence users to rotate all credentials after attackers breached its own cloud via unpatched TeamCity.
AI safety nonprofit METR says attackers stole an API key and burned about $600,000 in model credits across two incidents.
Three maximum-severity bugs in the ServiceNow AI Platform can be exploited without authentication.
Microsoft says the maximum-severity Entra ID flaw is fully mitigated and needs no customer action.
Attackers used an unknown Metabase flaw to grab admin access and customer data before a patch shipped.