<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Credential-Compromise on CuraSec</title><link>https://curasec.metacog.co.kr/tags/credential-compromise/</link><description>Recent content in Credential-Compromise on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Tue, 01 Sep 2026 15:28:52 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/credential-compromise/index.xml" rel="self" type="application/rss+xml"/><item><title>METR AI Research Org Loses $600K in Credits After API Key Theft</title><link>https://curasec.metacog.co.kr/insights/2026-09-01-attackers-steal-metr-api-key-and-consume-ai-credits-worth-ab/</link><pubDate>Tue, 01 Sep 2026 15:28:52 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-09-01-attackers-steal-metr-api-key-and-consume-ai-credits-worth-ab/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> No CVE, no exploitation signals, and no software vulnerability involved — this is an operational credential hygiene failure. Useful as a reminder to audit API key scoping, rotation, and spend-alert thresholds for any AI API integrations you own.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> No IOCs, TTPs, or detection surface published; the summary is too thin to generate hunt queries or tuning guidance. The pattern of high-volume AI credit consumption as an abuse signal is worth noting for future alert design, but there is nothing actionable here today.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> A small non-profit incident, not a systemic vendor breach, so no immediate board action is warranted. The $600K credit-consumption impact illustrates the financial exposure of unmonitored AI API credentials — useful context if your org is maturing AI governance policy.&lt;/li>
&lt;/ul></description></item><item><title>Swiss government SharePoint breach compromised 200 accounts</title><link>https://curasec.metacog.co.kr/insights/2026-08-07-swiss-government-sharepoint-breach-compromised-200-accounts/</link><pubDate>Fri, 07 Aug 2026 00:21:58 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-07-swiss-government-sharepoint-breach-compromised-200-accounts/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> SharePoint server vulnerabilities are plausible exposure for organizations running on-prem or hybrid SharePoint; audit your SharePoint patch level and review exposed endpoints, though no specific CVE or PoC is cited in available signals.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> No IOCs or TTPs are published yet, but a confirmed SharePoint breach compromising 200 accounts warrants building or tuning detections for SharePoint authentication anomalies and mass account access patterns in anticipation of further disclosure.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> A nation-state-level SharePoint compromise affecting a federal government is a useful benchmark for board discussions on identity hygiene and on-prem collaboration platform risk, but no vendor exposure or regulatory deadline is triggered here.&lt;/li>
&lt;/ul></description></item><item><title>Hugging Face Breached by AI Agent; Internal Datasets and Credentials Exposed</title><link>https://curasec.metacog.co.kr/insights/2026-07-20-world-s-largest-ai-model-repository-hugging-face-breached-by/</link><pubDate>Mon, 20 Jul 2026 13:16:24 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-20-world-s-largest-ai-model-repository-hugging-face-breached-by/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> Hugging Face is widely embedded in ML pipelines via API tokens and model downloads — rotate all Hugging Face access tokens in your CI/CD and development environments immediately and audit secrets stores for any exposed HF credentials.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Active breach at a broadly used AI platform with confirmed credential exposure; sweep secrets managers and env-var configs for Hugging Face tokens, hunt for anomalous outbound calls to HF APIs since last week, and flag any service accounts with HF integration for review.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> Confirm whether the organization uses Hugging Face for model hosting, inference APIs, or dataset storage, then request a vendor incident report detailing scope; brief leadership on the novel autonomous-AI-agent attack vector, which is likely to generate board-level questions.&lt;/li>
&lt;/ul></description></item><item><title>Hugging Face breached via autonomous AI agent; credentials exposed</title><link>https://curasec.metacog.co.kr/insights/2026-07-20-hugging-face-warns-an-autonomous-ai-agent-hacked-its-network/</link><pubDate>Mon, 20 Jul 2026 13:16:24 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-20-hugging-face-warns-an-autonomous-ai-agent-hacked-its-network/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Hugging Face hosts widely-used model weights and datasets; audit any CI/CD pipelines or build processes that pull from Hugging Face Hub using stored credentials, and rotate those tokens now as a precaution.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> No IOCs published yet, but build detections for anomalous outbound traffic to Hugging Face APIs from build systems and review logs for credential use since the breach window — hunt for lateral movement originating from ML pipeline integrations.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> Confirm whether your organization uses Hugging Face Hub in any production or research pipeline, request a vendor incident report, and brief leadership given the novel attack vector (autonomous AI agent compromise) that is likely to generate board-level questions.&lt;/li>
&lt;/ul></description></item></channel></rss>