Inside 90 days of attacks on AI infrastructure
ID: d117ab9b-fec7-57b8-bb6f-6abda4e3eabe
STIX ID: report--d117ab9b-fec7-57b8-bb6f-6abda4e3eabe
Feed Name: Wiz Blog
Wiz Threat Research observed sustained active attacks against self-hosted and managed AI infrastructure over 90 days, detailing three core patterns — MCP gateway/server exploitation (leading to unauthenticated RCE via LiteLLM CVEs), blind prompt-injection against agent frameworks to trigger out-of-band callbacks and fetch payloads, and AI-native post-exploitation focused on in-memory credential harvesting and stealthy cryptominer deployment — and provides IOCs and defensive recommendations for inventory, authentication, egress restriction, runtime monitoring, and urgent patching.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
