Hackers Are Targeting AI Servers to Steal API Keys and Hijack Computing Power
ID: bff7a582-4d86-5054-b816-c82171ab0dc4
STIX ID: report--bff7a582-4d86-5054-b816-c82171ab0dc4
Feed Name: GBHackers
Microsoft-observed attacks targeted AI gateways (LiteLLM), retrieval platforms (RAGFlow), and workflow orchestration (Kestra) to steal model-provider API keys and runtime secrets, achieve unauthenticated remote code execution by chaining CVE-2026-42271 and CVE-2026-48710 (LiteLLM) and exploiting CVE-2026-49869 (Kestra), and deploy cryptomining infrastructure; the report includes credential-harvesting techniques, IOCs (IPs, domains, ports), and mitigation recommendations such as patching, limiting exposure, and rotating secrets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
