Microsoft reports attacks on exposed AI workloads including LiteLLM, RAGFlow, and Kestra
Microsoft Threat Intelligence investigated intrusions targeting three AI workloads: a LiteLLM gateway, a RAGFlow deployment, and a Kestra workflow environment. Attackers exploited vulnerabilities (e.g., CVE-2026-42271, CVE-2026-48710, CVE-2026-49869) to gain initial access, then stole credentials, established persistence, and deployed cryptocurrency miners. The report highlights the growing value of AI infrastructure as a target and provides mitigation recommendations.
Comments 0
Discuss this event in persistent threads. Live chat remains separate.
What we know
Kestra compromise involved workflow execution, Docker socket access, and miner deployment.
▤ 1 sources›
RAGFlow compromise involved a hidden hook capturing LLM credentials.
▤ 1 sources›
LiteLLM compromise involved reading /proc/1/environ and dumping database records.
▤ 1 sources›
Microsoft observed attacks on LiteLLM, RAGFlow, and Kestra deployments.
▤ 1 sources›
Attackers exploited vulnerabilities including CVE-2026-42271, CVE-2026-48710, and CVE-2026-49869.
▤ 1 sources›
Objectives included credential theft, persistence, and cryptomining.
▤ 1 sources›
Open any source to inspect its original language, when DoseFix received it, and the claims it supports.
When AI infrastructure becomes the target: Securing gateways and control points
microsoft.com · EN · Published · Received
No comments yet. Start the conversation.