The Example Key From the Setup Guide (09/10/2026)

September 10, 2026
The Example Key From the Setup Guide (09/10/2026)
Key Intel / TL;DR
  • Wiz Research found nearly one in ten internet-facing LiteLLM gateways accepted sk-1234, the placeholder admin key printed in LiteLLM's own setup guide.
  • CISA added Cisco, Citrix, and Fortinet flaws to the KEV catalog with a September 12 federal patch deadline.
  • A kit called Blue Moon targeting Chrome and Windows is being read as evidence that AI is shortening the gap between disclosure and working exploit.
  • Anthropic disclosed a fourth incident in which one of its models broke into real third-party systems.
  • CISA confirmed ransomware crews are now exploiting a critical WatchGuard Firebox flaw it flagged in December.

The placeholder credential in a product’s own quickstart guide is the oldest failure in this business, and it has now arrived in the AI gateway layer with the paint still wet. What makes today’s finding worth more than a familiar sigh is where those gateways sit, since the thing behind them is a paid model account with an organization’s prompts and data running through it.

Top 5 Critical Security Alerts

1. One in Ten Exposed AI Gateways Took the Documentation’s Own Key

Wiz Research scanned internet-facing LiteLLM servers and found nearly one in ten accepted sk-1234, the example admin key printed in LiteLLM’s setup guide, which grants administrative control of the gateway a company puts between its applications and the model providers it pays. Anybody with that key can read the traffic passing through, mint their own keys, and spend the organization’s model budget, all through an interface built to look like ordinary API usage. This layer went from nonexistent to load-bearing in about eighteen months and got deployed by application teams rather than by anybody who runs a hardening baseline. The Hacker News has the research.

Operator Note: Find every AI gateway or proxy in your environment, confirm it is not reachable from the internet, and rotate the admin key regardless of what you believe it was set to.

2. CISA Sets a September 12 Deadline on Cisco, Citrix, and Fortinet

CISA added three actively exploited flaws to the Known Exploited Vulnerabilities catalog, one each in Cisco, Citrix, and Fortinet products, and gave federal civilian agencies until September 12, 2026 to patch. All three vendors sit at the network edge, which means these are the devices holding the remote access path rather than sitting behind it. A two-day federal deadline is the agency’s way of saying the exploitation is broad enough that it expects the window to close fast. The Hacker News has the catalog additions.

Operator Note: Treat a KEV entry on an edge appliance as an emergency change regardless of your own severity scoring, because the exploitation is already confirmed and your CVSS math cannot argue with that.

3. The Gap Between Rumor and Working Exploit Keeps Shrinking

Researchers documented a kit called Blue Moon targeting Chrome and Windows, and the analysis reads it as evidence of how much AI tooling has compressed exploit development. Bruce Schneier described being able to hand an agent nothing more than a rough rumor of what a flaw involved and have it locate the bug, which would have allowed exploitation well before the public patch existed. The practical consequence is that the interval you have been treating as a buffer between disclosure and weaponization is now considerably shorter than the interval your change process needs. The Register has the kit analysis and Schneier on Security has the demonstration.

4. Anthropic Reports a Fourth Model-Driven Intrusion

Anthropic disclosed a fourth incident in which one of its models broke into real third-party systems, in this case involving Claude Opus 4.6, adding to a short but growing public record of autonomous agents acting against live infrastructure. The disclosures matter more as a measurement problem than as a vendor story, because most organizations have no way to tell an agent-driven intrusion from a human one in their own logs. Attribution aside, the traffic looks like a competent operator working faster than a person can. The Hacker News has the disclosure and Infosecurity Magazine has the context.

Operator Note: Your detection thresholds assume a human pace of enumeration and lateral movement, so review anything tuned around “too fast to be a person” as a benign signal.

5. A WatchGuard Firewall Flaw Is Now Ransomware Infrastructure

CISA confirmed that ransomware crews are exploiting a critical remote code execution flaw in WatchGuard Firebox firewalls, a vulnerability the agency first flagged as actively exploited back in December. A nine-month gap between the first exploitation warning and confirmed ransomware use is the ordinary lifecycle of an edge flaw, and it says the population of unpatched devices stayed large enough to be worth industrializing. Firewalls are the appliances most likely to be running whatever firmware they shipped with. BleepingComputer has the confirmation.

Additional Security Alerts

Security Breaches and Incidents

  • Trezor warns of phishing after an email provider breach: Attackers who compromised the hardware wallet maker’s third-party email provider are now targeting its customers directly, which is the ordinary second stage of a vendor mail compromise. BleepingComputer
  • A dental contractor left behind a secret account reaching 4,000 patient records: The account was created during the engagement, went unnoticed, and outlived the contractor’s departure, which is what an offboarding process looks like when it only covers the accounts you issued. The Register

Law Enforcement and Policy

  • Treasury sanctions and the DOJ disrupts the Xinbi Guarantee marketplace: OFAC sanctioned the Chinese scam services platform while the DOJ seized its Telegram channels and $52.8 million across 52 cryptocurrency wallets. Infosecurity Magazine, The Hacker News, and The Record
  • The FBI published its first cyber strategy: The document leans on proactive disruption of threat actors, continuing a wider shift in how US agencies describe their role. Infosecurity Magazine

The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.

Distribute Intel
Chris Armour
Director of Information Security
Chris Armour
The Breaker & Builder.

Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.

View Profile →
Press & Media

Media Inquiries

For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.

Initialize Terminal

Initiate
Deployment.

Whether you need a full adversarial facility audit or an executive resilience protocol for your leadership team.

Secure the Facility (Assessments)
Secure the Mind (Coaching/Speaking)