logo

Hackers Are Targeting AI Servers to Steal API Keys and Hijack Computing Power

ID: bff7a582-4d86-5054-b816-c82171ab0dc4

STIX ID: report--bff7a582-4d86-5054-b816-c82171ab0dc4

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-08-27

Date Updated: 2026-08-27

Author: Mayura Kathir

...
...

Microsoft-observed attacks targeted AI gateways (LiteLLM), retrieval platforms (RAGFlow), and workflow orchestration (Kestra) to steal model-provider API keys and runtime secrets, achieve unauthenticated remote code execution by chaining CVE-2026-42271 and CVE-2026-48710 (LiteLLM) and exploiting CVE-2026-49869 (Kestra), and deploy cryptomining infrastructure; the report includes credential-harvesting techniques, IOCs (IPs, domains, ports), and mitigation recommendations such as patching, limiting exposure, and rotating secrets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.