logo

Hackers Target LiteLLM, RAGFlow and Kestra AI Infrastructure to Steal API Keys and Mine Crypto

ID: 58457734-01bf-5bf8-a801-067fc61c5464

STIX ID: report--58457734-01bf-5bf8-a801-067fc61c5464

Feed Name: Cyber Press

Threat Score
78/100

Date Published: 2026-08-27

Date Updated: 2026-08-27

Author: Varshini

...
...

Microsoft observed coordinated attacks against AI infrastructure components—LiteLLM, RAGFlow, and Kestra—where attackers exploited CVE-class flaws and misconfigurations to harvest environment variables and API keys, exfiltrate LLM provider credentials via hidden hooks, access databases, deploy XMRig cryptominers, and achieve persistent access; the report includes CVE references and IoCs (IP addresses and ports) to aid detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.