AINewsnow

An AI Vendor's Own Eval Sandbox Got Prompt-Injected Into Leaking Its Production API Keys — Then Attackers Used Them Against 30 More AI Companies

This story is from 2026-09-18. It is preserved in the archive; the latest stories are on the live feed.

The victim here builds AI products for a living. Its own automated evaluation pipeline still handed its production credentials to an attacker who simply asked for them in the input it was supposed to be grading. What the source says Anthropic's September 2026 threat intelligence report ("Detecting…

Read the full story at DEV Community — AI ↗

Timeline · 1 report

  1. 2026-09-18 09:01 · DEV Community — AI
    An AI Vendor's Own Eval Sandbox Got Prompt-Injected Into Leaking Its Production API Keys — Then Attackers Used Them Against 30 More AI Companies

More stories

  1. AI's role in building AI surging? Anthropic says Claude now leads 26% of its R&D — Mint AI
  2. Anthropic, OpenAI, SpaceXAI, Google sued over call to ‘pace’ AI development — Politico Technology
  3. Google Joins OpenAI, Anthropic, Meta in Disclosing AI Hacks — Bloomberg AI
  4. Novo Nordisk Will Use Anthropic’s Claude for Drug Research — Wall Street Journal Technology
  5. Gemini Hacked Three Companies in First Known Breakout by Google’s AI — Wall Street Journal Technology
  6. OpenAI discloses six new safety incidents — Axios AI+
  7. ‘Jailbreak-like...’: AI's ‘unexpected’ behaviour mounts concerns, OpenAI's 'rogue agents probed' Hugging Face — Mint AI
  8. Sources: Anthropic considers releasing a new AI model to counter OpenAI's momentum since Astra's launch, ahead of an IPO and after Amodei's call for a slowdown (Reuters) — Techmeme

Get the daily brief of stories like this at 6:30 every morning →