METR Research Non-Profit Suffers Security Incidents Involving API Key Theft and Unauthorized Access
Two separate incidents reported; API key compromised and AI credits consumed; no sensitive model data confirmed exfiltrated

Key Takeaways
- METR disclosed two security incidents involving unauthorized external access to its systems.
- An API key was stolen and used to consume AI credits valued at approximately $600,000.
- METR states that no sensitive model data or research information is believed to have been exfiltrated.
Related Security News

Times Car Confirms Data Breach Affecting 6.6 Million User Accounts
Times Car, a Japanese car-sharing service, has confirmed a data breach compromising approximately 6.6 million user accounts. The incident was disclosed late last week, with the exact attack vector and nature of exposed personal information yet to be fully specified. Authorities and the company are reportedly investigating the breach.

Unsloth Studio Vulnerability Enables Arbitrary Code Execution During Model Inspection
A vulnerability in Unsloth Studio's model inspection feature has been patched. The flaw allows malicious AI models to execute arbitrary Python code when the trust_remote_code setting is enabled, potentially compromising systems running the inspection tool. The issue has been addressed in a recent update, and users are advised to update to the latest version.



