CyberNotableConfirmedDeveloping
5.8
AI Evaluator METR Hit by Credential Theft, $600K in Model Credits Stolen
Dark Reading·US·about 2 hours ago
Threat actors are actively exploiting CVE-2026-0768, an unauthenticated remote code execution vulnerability in Langflow, to steal credentials, tokens, and keys from AI application environments. The attack targets OpenAI and AWS credentials, indicating a focused campaign against AI infrastructure. The full scope of affected organizations and data exfiltration remains unclear, but the exploitation of a critical flaw in a widely used open-source framework poses significant supply-chain risk.
Entities