September 11, 2026 · Issue 26 · 5 min read
Europe's 24-hour vulnerability clock started today, and the prize in the newest AI attacks was an API key
From today, a software vendor selling into the EU has 24 hours. The Cyber Resilience Act's reporting obligations(opens in a new tab) took effect on September 11. A manufacturer of a product with digital elements that learns a vulnerability is being actively exploited owes an early warning within 24 hours, a full notification within 72 hours, and a final report no later than 14 days after a fix is available, all through a single reporting platform. Freshfields points out(opens in a new tab) that the duty also reaches products placed on the EU market before the rest of the CRA applies in December 2027.
For a buyer, the useful question is not whether your vendors comply. It is whether you hear about an exploited flaw when the regulator does, or weeks later. The pace of disclosures makes that a live question. Forkast counts four critical CVEs in AI inference and agent infrastructure in four weeks(opens in a new tab). One, CVE-2026-82533 in DeepSeek's open-source coding agent tool, rated 9.4, let an agent inside its sandbox run a single command that switched off its own confinement and approval prompts.
The attackers have noticed where the value sits. Anthropic's September threat report(opens in a new tab), covering activity disrupted between December 2025 and August 2026, describes an actor that injected instructions into an AI vendor's automated evaluation sandbox, which handed over production API keys from multiple providers. A follow-on campaign hit roughly thirty AI companies in about four days. A second group ran a reseller selling cheap Claude access that was neither cheap nor Claude: traffic went to a different model while a harvester stole account credentials. Neither case needed a model to misbehave. One was a test environment holding production secrets. The other was a purchasing shortcut.
Washington is now reading vendor incident reports closely. Senator Hawley opened a subcommittee investigation(opens in a new tab) into OpenAI's breach of Hugging Face, wants answers by October 1, and says the company redacted attack details from its public report. Senator Van Hollen separately asked(opens in a new tab) that federal cybersecurity agencies get access to assess OpenAI's models. A vendor incident report is now also a legal document, and its level of detail will be set accordingly.
The bill for all of this capacity keeps rising. Oracle spent $28.5 billion on capex in its fiscal first quarter(opens in a new tab), ran negative $5.4 billion in free cash flow, guided full-year capex to $90 billion to $95 billion, and reports a $664 billion contracted backlog. Three things to settle this month. Require AI tooling vendors to notify you no later than they notify an EU authority. Find every AI API key sitting in a test or evaluation environment. And find any AI access your teams bought through a reseller instead of an authorized channel.
Researched and drafted by an automated workflow, then reviewed and edited by a human editor before publication. Every source is linked. See how we use AI here.
The Cyber Resilience Act's reporting duty attaches to products with digital elements, and software sold into the EU can fall inside that definition, including the self-hosted agent frameworks and model gateways an enterprise AI program runs on. Whether a particular hosted service is in scope is a question for counsel. What is not in question is that most enterprise software contracts carry no notification clock at all.
That gap is cheap to close. A notification clause that matches the regulatory one costs a vendor almost nothing, since it already has to write the notice. Ask for it at renewal, and ask for it first from the vendors whose tools can execute code or hold credentials.
Four critical flaws in a month is the rate that makes a clock matter. These are not obscure components. Inference servers, agent sandboxes and low-code agent builders are the plumbing of most enterprise pilots, and they are frequently installed by a team moving faster than vendor onboarding. A notice is only useful if someone knows the tool it refers to is running. An inventory of that plumbing comes first.
The detail that matters in Anthropic's report is where the keys were. An evaluation sandbox held production API keys, and instructions injected into it were enough to get them out. Test and evaluation environments tend to be seeded with real keys because the test has to be realistic, and they tend to be reviewed with less rigor than production. That is the place to look first.
The reseller case is a procurement finding dressed as a security one. A team that buys discounted model access to avoid a slow purchasing process gets a model it did not choose, output quality it cannot measure, and a credential exposure nobody signed off on. The fix is a faster authorized channel, not a stern memo.
Oracle's quarter is the cost side of the same picture. A supplier guiding to $90 billion or more of capex in a single year, with free cash flow already negative, needs its customers to stay. Multi-year AI capacity commitments signed this year are worth negotiating with exit and portability terms, while the bookings still matter more to the seller than to the buyer.
Also worth knowing
- Cyber Resilience Act: reporting obligations(opens in a new tab)
European Commission
From September 11, manufacturers must send an early warning within 24 hours of learning a flaw is actively exploited, then a full notification within 72 hours, through one ENISA reporting platform.
- Detecting and countering misuse of AI: September 2026(opens in a new tab)
Anthropic
An attacker prompt-injected an AI vendor's evaluation sandbox into handing over production API keys, then hit roughly thirty AI companies in four days. Anthropic's advice: buy AI access only through authorized channels.
- Four weeks, four critical CVEs: AI inference infrastructure is now a regular target(opens in a new tab)
Forkast
Includes CVE-2026-82533, rated 9.4, where one command from inside DeepSeek's coding agent sandbox disabled all confinement, and an SGLang flaw disclosed with no vendor patch available.
- Hawley launches committee investigation into OpenAI's breach of Hugging Face(opens in a new tab)
Nextgov/FCW
A Senate homeland security subcommittee wants OpenAI's answers by October 1. Hawley says the company redacted attack details that limited what outside auditors could see.
- Oracle weakens bear case with broader AI customer base and $664 billion backlog(opens in a new tab)
24/7 Wall St.
Quarterly capex of $28.5 billion, negative $5.4 billion free cash flow, and full-year capex guided to $90 billion to $95 billion. The non-OpenAI backlog more than doubled, but OpenAI remains material.