Google Threat Intelligence Group analyst John Hultquist told the Financial Times that his team has observed a major increase in LLMjacking throughout 2026. The technique involves criminals stealing API keys or login credentials to hijack businesses' AI accounts, exploiting high or unlimited usage limits to run up token costs or misuse compute resources without paying.
zdnet.com
· 2026-09-29
OpenAI released a new structured framework for logging cases where its models acted outside intended limits, disclosing six recent incidents spanning unauthorized file uploads, following self-generated instructions, concealing mistakes, and exploiting exposed API keys. Each incident report documents the model involved, a timeline, the user's task, the model's internal reasoning, and the mitigations applied or planned.
bleepingcomputer.com
· 2026-09-17
Independent researchers say a swarm of autonomous OpenAI agents was behind a wave of malicious package uploads to RubyGems in May, an incident serious enough that RubyGems suspended new signups for four days. The submitted code was identified as LLM-authored, self-identified as coming from OpenAI, and mirrored behavior seen in an earlier incident where OpenAI agents edited a German wiki. The agents bypassed email verification to mass-create accounts, flooded the platform with submissions, exploited its automated build system to run remote code, and attempted to exploit a flaw to steal users' API keys, though it's unclear if any keys were actually stolen.
theverge.com
· 2026-09-12