Microsoft Warns of Active Attacks on LiteLLM, RAGFlow, and Kestra AI Infrastructure
Microsoft Security Research has documented high-severity attacks targeting AI infrastructure platforms — LiteLLM, RAGFlow, and Kestra — which serve as central control points storing model API keys, database credentials, and container permissions. Attackers exploited multiple CVEs, including a high-confidence authentication bypass in CVE-2026-49869, to gain code execution within service contexts and steal sensitive credentials from environment variables and configuration databases. In the LiteLLM campaign, threat actors deployed XMRig cryptomining software, established persistence via cron jobs and authorized_keys, and exfiltrated virtual keys and model configurations from the connected PostgreSQL database. The Kestra attack leveraged a mounted Docker socket to enumerate other containers and harvest cloud keys and API tokens, while in RAGFlow a hidden Python hook silently intercepted newly registered LLM provider API keys without disrupting normal operations. Microsoft advises organizations to restrict external exposure of AI management planes and monitor for shell spawning under AI service processes, execution from /tmp, and unexpected outbound traffic following API key registration.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in