AI Gateway Exploitation: How Attackers Are Targeting LiteLLM, RAGFlow, and Kestra to Steal Your Model Provider Keys
ID: 3471b278-133f-5ad4-a839-d3ec9eb1234b
STIX ID: report--3471b278-133f-5ad4-a839-d3ec9eb1234b
Feed Name: Brandefense Blog
Threat Score
This technical intelligence report documents active, high-severity campaigns (INT-2608-e7a5) targeting AI gateway and orchestration platforms—LiteLLM, RAGFlow, and Kestra—describing chained unauthenticated RCEs and path traversal vulnerabilities (multiple CVEs including CVSS 10.0 cases), observed credential theft and host compromise, IOCs, and recommended immediate mitigations including urgent patching, network segmentation, and secret-management best practices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
