Microsoft reports attacks on exposed AI workloads including LiteLLM, RAGFlow, and Kestra
Microsoft Threat Intelligence investigated intrusions targeting three AI workloads: a LiteLLM gateway, a RAGFlow deployment, and a Kestra workflow environment. Attackers exploited vulnerabilities (e.g., CVE-2026-42271, CVE-2026-48710, CVE-2026-49869) to gain initial access, then stole credentials, established persistence, and deployed cryptocurrency miners. The report highlights the growing value of AI infrastructure as a target and provides mitigation recommendations.
What we know
Kestra compromise involved workflow execution, Docker socket access, and miner deployment.
▤ 1 sources›
RAGFlow compromise involved a hidden hook capturing LLM credentials.
▤ 1 sources›
LiteLLM compromise involved reading /proc/1/environ and dumping database records.
▤ 1 sources›
Microsoft observed attacks on LiteLLM, RAGFlow, and Kestra deployments.
▤ 1 sources›
Attackers exploited vulnerabilities including CVE-2026-42271, CVE-2026-48710, and CVE-2026-49869.
▤ 1 sources›
Objectives included credential theft, persistence, and cryptomining.
▤ 1 sources›
Microsoft Threat Intelligence observed attacks targeting exposed AI infrastructure, including LiteLLM gateway, RAGFlow, and Kestra, with attackers stealing credentials, establishing persistence, and deploying cryptominers.
Verified · 1 sourcesLive reports
View allComments 0
Discuss this event in persistent threads. Live chat remains separate.
No comments yet. Start the conversation.