An AI Vendor's Own Eval Sandbox Got Prompt-Injected Into Leaking Its Production API Keys — Then Attackers Used Them Against 30 More AI Companies
This story is from 2026-09-18. It is preserved in the archive; the latest stories are on the live feed.
The victim here builds AI products for a living. Its own automated evaluation pipeline still handed its production credentials to an attacker who simply asked for them in the input it was supposed to be grading. What the source says Anthropic's September 2026 threat intelligence report ("Detecting…
Read the full story at DEV Community — AI ↗
Timeline · 1 report
- 2026-09-18 09:01 · DEV Community — AI
An AI Vendor's Own Eval Sandbox Got Prompt-Injected Into Leaking Its Production API Keys — Then Attackers Used Them Against 30 More AI Companies