CVE-2026-42271
Sfruttamento noto · CISA KEV
CVSS 8.8 HIGH: liteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. EPSS 93% (100º percentile).
Data di correzione federale CISA 22 giu · data superata
Vulnerabilità ed exploit · Cryptojacking
Lumen Black Lotus Labs ha attribuito a PoeLLM più di 3.400 server compromessi dal mese di aprile. La campagna non si limita a fare cryptomining su LiteLLM, Ollama, Gotenberg e Gitea esposti: usa anche i gateway AI/LLM infetti per cercare nuove vittime, quindi amplia il raggio d’azione oltre il singolo host.
Il malware non tiene fisso il proprio C2. Recupera l’indirizzo da una poesia pubblicata su GitHub e lo ricostruisce da quattro parole selezionate, così l’infrastruttura può cambiare senza un indicatore di rete ovvio da bloccare. Black Lotus Labs collega la prima esposizione a Ivanti Sentry e indica anche CVE-2026-10520 e CVE-2026-42271 come parte del contesto di compromissione.
Per chi espone LiteLLM, Ollama o servizi analoghi, il punto non è solo il consumo di CPU. Un gateway già preso può diventare un punto di appoggio per scansioni verso altri bersagli e può trascinarsi dietro accessi o dati che il servizio riesce a raggiungere o trattare, anche dopo la rimozione del miner.
5 fonti · 8 ott
Sfruttamento noto · CISA KEV
CVSS 8.8 HIGH: liteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. EPSS 93% (100º percentile).
Data di correzione federale CISA 22 giu · data superata
Sfruttamento noto · CISA KEV
CVSS 10 CRITICAL: an OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a…
Data di correzione federale CISA 14 giu · data superata
Help Net Security
Cryptomining botnet hides C2 addresses in GitHub poem, infects over 3,400 servers - Help Net Security
PoeLLM malware reads a GitHub poem to find its C2 servers and has hit more than 3,400 servers, mostly AI tools like LiteLLM and Ollama.
originaleThe Register Security
Poetry is the new AI security threat as PoeLLM malware infects 3K+ servers
Quoth the LLM, 'More and more'
originaleThe Hacker News
PoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining Botnet
Canto Incognito has infected over 3,400 servers, using exposed AI and LLM infrastructure for crypto mining and botnet growth.
originalePart of the PlainSec briefing for 2026-10-07
Every edition of this story: I gateway AI infetti diventano anche scanner offensivi