AI Token Jacking: Stolen API Keys Fueled Nearly $1M Bills
Unit 42 says criminals added stolen AI API keys to gray-market proxy services within minutes, creating nearly $1 million in charges. Learn the warning signs and response order.
News desk
Security incidents, exploited vulnerabilities, breach reports, malware campaigns, and urgent patch notes arranged for fast daily scanning.
August 7, 2026
Unit 42 says criminals added stolen AI API keys to gray-market proxy services within minutes, creating nearly $1 million in charges. Learn the warning signs and response order.
See what is verified about Heisenberg RAT, how hidden desktops can expose browser sessions, and how to isolate, scan, and recover accounts safely.
Unit 42 showed how malware on Chrome for Windows can abuse synced Google passkeys. Learn who is affected, what was fixed, and how to…
N-central CVE-2026-18577 is under active attack. Install 2026.3.1.7, then check Take Control logs, Cloudflared services, and downstream endpoints.
Arch temporarily stopped AUR pushes after malicious package takeovers. Check openconnect-sso exposure, Linux persistence, stolen secrets, and the right recovery order.
Rails patched CVE-2026-66066 in Active Storage. Check whether your app uses vulnerable libvips processing, update, rotate exposed secrets, and inspect official forensic evidence.
Coldcard weak seed generation affects Mk3 and earlier Mk4, Mk5, and Q releases. Updating stops new weak seeds but does not repair an existing…
A compromised Adform tracking script could replace Bitcoin, Ethereum, and Tron recipient addresses while an affected page was open. Check transfers and clear browser…
Crypto.com warns of targeted phishing emails about unfamiliar activity and fake bank-account changes. Check the Anti-Phishing Code, verify safely, and recover by exposure stage.