logo

AI Gateway Exploitation: How Attackers Are Targeting LiteLLM, RAGFlow, and Kestra to Steal Your Model Provider Keys

ID: 3471b278-133f-5ad4-a839-d3ec9eb1234b

STIX ID: report--3471b278-133f-5ad4-a839-d3ec9eb1234b

Feed Name: Brandefense Blog

Threat Score
90/100

Date Published: 2026-08-31

Date Updated: 2026-08-31

Author: Onur Can Arslan

...
...

This technical intelligence report documents active, high-severity campaigns (INT-2608-e7a5) targeting AI gateway and orchestration platforms—LiteLLM, RAGFlow, and Kestra—describing chained unauthenticated RCEs and path traversal vulnerabilities (multiple CVEs including CVSS 10.0 cases), observed credential theft and host compromise, IOCs, and recommended immediate mitigations including urgent patching, network segmentation, and secret-management best practices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.