CVE-2026-42271
Known exploited · CISA KEV
CVSS 8.8 HIGH: liteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. EPSS 93% (100th percentile).
CISA federal remediation date Jun 22 · date passed
Threats · 4h ago
Lumen’s Black Lotus Labs says PoeLLM has infected more than 3,400 exposed AI and LLM servers since April, turning them into a cryptomining botnet that also scans for more victims. The campaign has hit internet-facing systems including LiteLLM, Gotenberg, Gitea, and Ivanti Sentry, and it continues to grow.
The malware does not carry a fixed command-and-control address. Instead, it reads a few words from a poem hosted on GitHub, combines them with a hard-coded dictionary, and reconstructs the real C2 server from that harmless-looking text. That makes the coordination point harder to spot and shift than a normal domain or IP blacklist, while infected hosts are also reused as scanners and exploit launchpads.
For teams running exposed AI services or other public-facing appliances, the exposure is not just wasted CPU from mining. A single foothold can become a node in someone else’s attack infrastructure, and cleanup that focuses only on mining leaves the scanning and downstream-compromise role intact until the infected host is removed.
Known exploited · CISA KEV
CVSS 8.8 HIGH: liteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. EPSS 93% (100th percentile).
CISA federal remediation date Jun 22 · date passed
Known exploited · CISA KEV
CVSS 10 CRITICAL: an OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a…
CISA federal remediation date Jun 14 · date passed
Known exploited · CISA KEV
CVSS 6.5 MEDIUM: starlette is a lightweight ASGI framework/toolkit.
CISA federal remediation date Sep 16 · date passed
4 sources covering this story
Poetry is the new AI security threat as PoeLLM malware infects 3K+ servers
Quoth the LLM, 'More and more'
PoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining Botnet
Canto Incognito has infected over 3,400 servers, using exposed AI and LLM infrastructure for crypto mining and botnet growth.
PoeLLM malware infects exposed AI servers in cryptomining attacks
A cryptomining campaign targeting exposed AI services is using PoeLLM malware to turn compromised servers into scanners and exploit launchpads.
PoeLLM malware has assembled a sweeping botnet, taking technical cues from a poem
More than 3,400 servers have been compromised by malware that hides its infrastructure coordinates in a poem.
Part of the PlainSec briefing for 2026-10-07