CVE-2026-42271
Sfruttamento noto · CISA KEV
CVSS 8.8 HIGH: liteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. EPSS 93% (100º percentile).
Data di correzione federale CISA 22 giu · data superata
Minacce · 4 ore fa
PoeLLM ha compromesso oltre 3.400 server esposti e li ha trasformati in una botnet che non si limita a fare cryptomining. L'impatto è più ampio del consumo di CPU: i nodi infetti vengono riusati per cercare altre vittime e per rilanciare nuovi attacchi.
Il malware non punta a un indirizzo C2 fisso. Ricava la destinazione da poche parole prese da un poem pubblicato su GitHub, che a vista sembra testo innocuo; cambiando quei termini, l'operatore può spostare il controllo senza appoggiarsi a infrastrutture pubbliche facili da bloccare. Questo rende più difficile spegnere la campagna con i soli indicatori di rete.
Per chi espone LiteLLM, Gotenberg, Gitea, Ivanti Sentry o servizi simili, il problema non è solo l'infezione iniziale. Un server compromesso può diventare un proxy, uno scanner e un trampolino per compromissioni successive, anche dopo la rimozione del miner.
Sfruttamento noto · CISA KEV
CVSS 8.8 HIGH: liteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. EPSS 93% (100º percentile).
Data di correzione federale CISA 22 giu · data superata
Sfruttamento noto · CISA KEV
CVSS 10 CRITICAL: an OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a…
Data di correzione federale CISA 14 giu · data superata
Sfruttamento noto · CISA KEV
CVSS 6.5 MEDIUM: starlette is a lightweight ASGI framework/toolkit.
Data di correzione federale CISA 16 set · data superata
4 fonti che coprono questa storia
Poetry is the new AI security threat as PoeLLM malware infects 3K+ servers
Quoth the LLM, 'More and more'
PoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining Botnet
Canto Incognito has infected over 3,400 servers, using exposed AI and LLM infrastructure for crypto mining and botnet growth.
PoeLLM malware infects exposed AI servers in cryptomining attacks
A cryptomining campaign targeting exposed AI services is using PoeLLM malware to turn compromised servers into scanners and exploit launchpads.
PoeLLM malware has assembled a sweeping botnet, taking technical cues from a poem
More than 3,400 servers have been compromised by malware that hides its infrastructure coordinates in a poem.
Part of the PlainSec briefing for 2026-10-07