Tech
AI evaluation startup Braintrust confirms breach, tells every customer to rotate sensitive keys
AI evaluation startup Braintrust has urged customers to revoke and replace their API keys after an earlier breach of customer secrets.
According to an email sent to customers Monday and seen by TechCrunch, the startup confirmed “unauthorized access” in one of its Amazon Web Services cloud accounts, which contained API keys used by customers for accessing cloud-based AI models.
“We’ve communicated with one impacted customer and to date have not found evidence of broader exposure,” read the email.
The email asked “every customer to rotate” any of the API keys that they store with Braintrust.
Braintrust disclosed the security incident on its website on Tuesday. “The incident has been contained, and in the meantime, we’ve locked down the compromised account, audited and restricted access across related systems, and rotated internal secrets.”
The company said the cause of the breach is under investigation.
Braintrust spokesperson Martin Bergman told TechCrunch that the company sent the email to customers “out of an abundance of caution,” and that it “confirmed a security incident, but there is no evidence of a breach at this time.”
Techcrunch event
San Francisco, CA
|
October 13-15, 2026
Braintrust provides a platform designed for companies to monitor AI models and products. Founder and CEO Ankur Goyal previously told TechCrunch that Braintrust is like an “operating system for engineers building AI software.” The startup raised $80 million in a Series B funding round in February, which valued the company at $800 million.
Jaime Blasco, the co-founder of cybersecurity startup Nudge Security who received a breach email alert from Braintrust, told TechCrunch that the incident could have “downstream implications for affected customers,” like AI companies that rely on Braintrust.
Contact Us
Do you have more information about this breach? Or other data breaches? From a non-work device, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Telegram and Keybase @lorenzofb, or email.
Hackers frequently target corporate accounts on cloud services or third-parties platforms as an effective way of stealing secrets, like API keys. Once hackers get their hands on API keys, they can log into the company or customers’ systems appearing as if they are legitimate users, without needing to break into the target company’s systems.
CircleCI, a company that provides development products for software engineers, was hit with a similar cloud data breach in 2023, and similarly asked its customers to rotate “any and all secrets” they stored with the company.
More recently, a EU cybersecurity agency said hackers were able to steal 92 gigabytes of data from a compromised Amazon Web Services (AWS) account used by the European Commission. The breach affected 29 other EU entities and the data of dozens of internal European Commission clients.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
>
Tech
Meta Wants to Run Your Business With AI — Microsoft and Salesforce Have a New Rival
Meta launches Enterprise Platform, bringing Muse, Business Agent and AI tools to companies as it takes on Microsoft and Salesforce.
The post Meta Wants to Run Your Business With AI — Microsoft and Salesforce Have a New Rival appeared first on TechRepublic.
>
Tech
OpenAI gives Codex reusable cloud environments that work across devices
OpenAI introduced new capabilities for its software engineering agent Codex, making it more useful beyond a developer’s laptop with reusable cloud development environments that can be accessed from any device.
The update, announced at OpenAI’s Dev Day on Tuesday, is one of several for Codex. OpenAI also announced a refreshed Codex CLI, a new code review experience, tools to harden infrastructure, and other API enhancements.
While Codex could already spin up cloud tasks to do work remotely, today’s announcement shows that OpenAI is making those cloud environments more persistent and configurable, rather than treating each cloud task as an isolated remote sandbox.
As the company explains, developers will now be able to run Codex wherever they need it, whether that’s on a computer, remotely from a phone, or in the cloud. The reusable development environments are designed to help tasks start more quickly and give teams a shared workspace with approved settings and permissions, OpenAI said.

Meanwhile, the Codex CLI is getting an update that allows developers to start and direct tasks using their voice.
A new /agents view is meant to make it easier to delegate work and track multiple tasks at the same time. Other changes include improvements to everyday tasks such as editing prompts, resuming sessions, and using worktrees. OpenAI is also rolling out a “cleaner” terminal user interface designed to make longer sessions easier to read.

Codex can also be pulled into a new code review experience within the ChatGPT desktop app, where users can read summaries, explore code changes, or ask Codex about potential issues before sharing feedback on GitHub pull requests or GitLab merge requests.
Automatic code reviews also let Codex perform an initial review while users step away from their computers.

On the security side, OpenAI is rolling out a new set of tools called Codex Security Cloud, designed to help developers secure their infrastructure. Developers can use the tools to scan entire GitHub repositories on demand or on a regular schedule, as well as whenever new commits arrive. Codex will then investigate findings, remove duplicates, and prepare fixes in the cloud — even when the user isn’t active and their laptop is closed.
Notably, the toolset includes access to the models offered through OpenAI’s cybersecurity initiative Daybreak Blue, without requiring developers to submit a separate application.

OpenAI also announced several API updates, including a new Decisions API for real-time decision-making. The API uses Luna to answer a set of user-defined questions with predefined answers. The company also introduced an updated a version of the Agents API that now supports computer use and the ability to use Amazon’s Bedrock Managed Agents to build OpenAI agents that run entirely on AWS.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
>
Tech
OpenAI takes on Microsoft with the launch of what feels a whole lot like ChatGPT’s own office suite
OpenAI has been a close partner of Microsoft from the jump, but the AI lab is increasingly going after the company’s bread and butter, workplace software, with new features that closely resemble an office software suite like Microsoft’s.
At its Dev Day developer conference in San Francisco on Tuesday, OpenAI announced several new ChatGPT features designed for office workers.
Most notably, OpenAI launched a feature called Space, a shared workspace inside ChatGPT where coworkers can collaborate with the chatbot and with their own Dots, OpenAI’s newly launched AI agent personas (that can carry out tasks on a user’s behalf), on a range of work tasks.
“Your pages and files all live together in Space, like they would in a drive,” said CEO Sam Altman during Tuesday’s presentation. “But spaces feel alive.” Altman said users can give a page specific instructions, such as checking a team channel and updating the page with what it finds.
OpenAI also announced Pages, a companion word processor that the company describes as “a new type of document, built for human and agent collaboration.” It appears to be OpenAI’s answer to Google Docs and Microsoft Word. Users can “write, research, generate charts, create images, or visualize information” in it, OpenAI says.
OpenAI has also launched its answer to PowerPoint with what it calls collaborative slides. These slides can be created by merely talking about them within ChatGPT. Once generated, multiple workers and agents can work together within them and will have the ability to leave comments and edit them.
As OpenAI edges into the territory of Microsoft, Microsoft and other software companies like Salesforce are busy trying to become more like OpenAI. Over the past year, both companies have released a slew of AI products as the software industry attempts to keep up with the shifting landscape.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
>
-
movies4 months agoSearch For Canadian TV Actor Stewart McLean Now Homicide Investigation
-
Fashion9 years agoThese ’90s fashion trends are making a comeback in 2017
-
Fashion9 years agoAccording to Dior Couture, this taboo fashion accessory is back
-
Fashion9 years agoModel Jocelyn Chew’s Instagram is the best vacation you’ve ever had
-
Fashion9 years agoEmily Ratajkowski channels back-to-school style
-
Fashion9 years ago9 Celebrities who have spoken out about being photoshopped
-
Anime4 months agoRurouni Kenshin: Hokkaido Arc Manga Takes 1-Issue Break – News
-
Anime3 months agoHIDIVE to Stream English Dubs for The World Is Dancing, The Forsaken Saintess and Her Foodie Roadtrip in Another World, The Dangers in My Heart: The Movie Anime – News
