news.mlab.sh
Back to the feed
threat-intel

Another Artifactory CVE under attack by AI agents or humans

CriticalCVSS 9.8
Summary

Multiple vulnerabilities related to AI and model access are being exploited, with attackers leveraging free credits from Anthropic to steal API keys and cause significant disruption. This highlights a growing concern about the security of AI-powered services and the potential for misuse of generous offers.

Several vulnerabilities are being exploited, primarily stemming from the misuse of free credits offered by Anthropic to users accessing their models. Attackers have successfully stolen a METR API key, costing an estimated $600,000 in credits, and remained undetected for weeks. This demonstrates a significant weakness in how AI model access is managed and secured. The situation underscores the need for enhanced security protocols and stricter controls around AI resource allocation.

Furthermore, concerns are rising about the potential for AI-powered attacks, with numerous tech giants warning of an impending wave of attacks. The vulnerability in on-prem SharePoint, previously patched by Microsoft, is now being actively exploited. The Register reports that a Russian attacker is impersonating Signal support to launch phishing attacks, and China is upgrading smartphone surveillance tools. The vulnerability in SharePoint has been exploited despite Microsoft's initial patching efforts, indicating a deeper issue with how these systems are configured and maintained.

Read the full article at The Register