Microsoft identifies AI infrastructure cyberattacks targeting LiteLLM and RAGFlow gateways
Microsoft Threat Intelligence has identified a pattern of cyberattacks targeting AI infrastructure components, specifically LiteLLM gateways, RAGFlow deployments, and Kestra orchestrators. Attackers are exploiting vulnerabilities in these services to harvest API keys, gain persistent host access, and monetize compute resources through cryptomining.
Key Takeaways
- LiteLLM gateway compromises involved harvesting model-provider API keys and master keys from the process environment.
- RAGFlow attacks utilized runtime hooks to intercept LLM provider credentials during the configuration flow.
- Kestra orchestrator breaches exploited CVE-2026-49869 to execute shell scripts and access Docker sockets.
- Attackers deployed XMRig miners and used MSR kernel module tuning to maximize CPU resource theft.
Why It Matters
These attacks signal a shift where AI gateways and orchestrators are now treated as high-value control planes by threat actors. For streaming platforms integrating generative AI, a compromise at the gateway level exposes not just individual models, but the entire credential stack and backend database configuration. This trend forces a reevaluation of the AI infrastructure power constraints as Tier-0 infrastructure, requiring the same security rigor as core content delivery networks. As streaming engineers deploy more retrieval-augmented generation workflows, they must monitor for application-origin shells and unauthorized Docker socket access. Watch for increased adoption of per-team virtual keys and managed secret stores to mitigate the impact of environment variable harvesting.
Additional Context
Microsoft has been expanding its AI security portfolio aggressively throughout 2025 and 2026, positioning Microsoft Defender as a unified platform for protecting AI workloads alongside traditional endpoints. In May 2025, Microsoft announced that Defender for Cloud now includes AI security posture management capabilities that automatically discover AI services, assess misconfigurations, and surface risks across cloud environments. This broader platform strategy gives Microsoft a vantage point into emerging attack patterns against AI infrastructure components like the LiteLLM gateways and RAGFlow deployments detailed in the latest threat intelligence report.
The regulatory environment around AI security is tightening in parallel. In March 2025, the U.S. National Institute of Standards and Technology released its AI Risk Management Framework Generative AI Profile, which provides specific guidance on securing AI supply chains and model-serving infrastructure. The profile identifies credential harvesting and unauthorized compute access as high-severity risks, directly mirroring the attack vectors Microsoft documented against LiteLLM and Kestra orchestrators. Meanwhile, the EU AI Act entered its enforcement phase in August 2025 with obligations for high-risk AI system providers to implement security controls and incident reporting, creating compliance pressure on streaming platforms that deploy generative AI pipelines.
On the technical front, LiteLLM has become one of the most widely adopted open-source LLM gateway proxies, and its rapid adoption has outpaced security hardening. In April 2025, researchers at Wiz disclosed multiple critical vulnerabilities in LiteLLM's proxy server, including server-side request forgery and authentication bypass flaws that could allow unauthenticated attackers to access backend model endpoints. Microsoft's threat intelligence findings align with those disclosures, confirming active exploitation in the wild rather than theoretical risk. For streaming infrastructure teams running RAG-based content recommendation or metadata enrichment pipelines, the combination of exposed gateway endpoints and hardcoded API keys in environment variables represents a concrete attack surface that demands immediate remediation through enterprise video compliance framework and network segmentation.
Read full article at microsoft.com
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source