Vulnerabilities · 31 days ago
Microsoft Broadens AI Gateway Abuse to Three Workloads On day 15, Microsoft said the LiteLLM activity has widened into a broader pattern across three AI workloads: LiteLLM, RAGFlow, and Kestra. The company said attackers are treating exposed AI gateways and workflow layers as control points for credential theft, persistence, and cryptomining, not just one-off product bugs.
The issue is the trust these services hold. Microsoft said they can sit on model-provider keys, virtual keys, database connection strings, tenant policy, and execution rights, so a foothold in the middle tier can be reused to reach the systems behind it; in LiteLLM’s case, the observed path includes CVE-2026-42271 .
For teams running AI gateways, orchestration, or agent tooling, the exposure lives in the management layer and whatever it can already access. Patching the visible flaw does not erase secrets or downstream paths if the service was already acting as the bridge between users, models, and internal systems.
NVD KEV
Known exploited · CISA KEV
CVSS 8.8 HIGH: liteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. EPSS 84% (100th percentile).
CISA federal remediation date Jun 22 · date passed
Timeline Sources 26 sources covering this story
BleepingComputer Aug 28
AI Is Accelerating Vulnerability Discovery. Can Defenders Keep Up?
AI is accelerating vulnerability discovery, putting pressure on systems built to enrich, prioritize, and remediate flaws at a slower pace.
Huntress Blog Aug 28
The AI Attack Surface: How Threat Actors Abuse Trusted AI Platforms | Huntress
Threat actors are targeting the AI attack surface to deliver malware and steal data. See how trusted AI tools are being exploited today.
Risky Biz News Aug 27
Srsly Risky Biz: China's AI-Enabled APT Operations Are Getting Interesting
Tom Uren and James Wilson talk about evidence that Chinese APT groups are using AI in a really sensible way, to beef up their malware arse [Read More
Microsoft Security Blog Aug 26
When AI infrastructure becomes the target: Securing gateways and control points | Microsoft Security Blog
Microsoft Threat Intelligence examines attacks on exposed AI workloads, including LiteLLM gateway exploitation, credential harvesting, persistence, and cryptomining activity.
Snyk Blog Aug 26
Why AI Applications Stay Exposed When Scans Pass | Snyk
Your scans came back clean, and the app is still exploitable. How chained risk forms across AI layers.
SentinelOne Aug 25
The Path to the Autonomous SOC: The Early Returns of AI & What It Means for Cybersecurity | SentinelOne
Discover how early-stage AI yields rapid SOC returns, driving platform consolidation and reducing analyst burnout in this blog post.
Unit 42 Aug 25
The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution
Explore Unit 42 research on AI-enabled malware. Learn how existing behavioral detection and endpoint analytics stop AI-authored code before execution.
Talos Intelligence Aug 25
The safety penalty: Reclaiming operational sovereignty in the age of AI
As frontier AI models become increasingly restrictive, security teams are facing a "safety penalty" that hampers real-time incident response. Discover how organizations can move toward operational sovereignty to ensure their defensive AI keeps pace with unconstrained adversaries.
Elastic Security Labs Aug 25
Agentic SOC alert triage: 60% to 92% AI accuracy — Elastic Security Labs
Inside the agentic SOC Elastic's InfoSec team runs in production: the three-agent pipeline, the analyst feedback loop, and the one-button close in Slack.
SecurityWeek Aug 24
Rethinking Application Security for the AI Era
As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk.
Industrial Cyber Aug 24
UK NCSC calls for risk-based controls as organizations deploy increasingly autonomous AI agents - Industrial Cyber
U.K. NCSC calls for risk-based controls as organizations deploy increasingly autonomous AI agents across complex workflows.
The Register Security Aug 22
If you're not using AI to attack your own systems, your adversaries will
Agents are also the new attack surface - cue defenders' existential angst
Part of the PlainSec briefing for 2026-08-25
Editions Related stories
Vulnerabilities · 31 days ago
Microsoft Broadens AI Gateway Abuse to Three Workloads On day 15, Microsoft said the LiteLLM activity has widened into a broader pattern across three AI workloads: LiteLLM, RAGFlow, and Kestra. The company said attackers are treating exposed AI gateways and workflow layers as control points for credential theft, persistence, and cryptomining, not just one-off product bugs.
The issue is the trust these services hold. Microsoft said they can sit on model-provider keys, virtual keys, database connection strings, tenant policy, and execution rights, so a foothold in the middle tier can be reused to reach the systems behind it; in LiteLLM’s case, the observed path includes CVE-2026-42271 .
For teams running AI gateways, orchestration, or agent tooling, the exposure lives in the management layer and whatever it can already access. Patching the visible flaw does not erase secrets or downstream paths if the service was already acting as the bridge between users, models, and internal systems.
NVD KEV
Known exploited · CISA KEV
CVSS 8.8 HIGH: liteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. EPSS 84% (100th percentile).
CISA federal remediation date Jun 22 · date passed
Timeline Sources 26 sources covering this story
BleepingComputer Aug 28
AI Is Accelerating Vulnerability Discovery. Can Defenders Keep Up?
AI is accelerating vulnerability discovery, putting pressure on systems built to enrich, prioritize, and remediate flaws at a slower pace.
Huntress Blog Aug 28
The AI Attack Surface: How Threat Actors Abuse Trusted AI Platforms | Huntress
Threat actors are targeting the AI attack surface to deliver malware and steal data. See how trusted AI tools are being exploited today.
Risky Biz News Aug 27
Srsly Risky Biz: China's AI-Enabled APT Operations Are Getting Interesting
Tom Uren and James Wilson talk about evidence that Chinese APT groups are using AI in a really sensible way, to beef up their malware arse [Read More
Microsoft Security Blog Aug 26
When AI infrastructure becomes the target: Securing gateways and control points | Microsoft Security Blog
Microsoft Threat Intelligence examines attacks on exposed AI workloads, including LiteLLM gateway exploitation, credential harvesting, persistence, and cryptomining activity.
Snyk Blog Aug 26
Why AI Applications Stay Exposed When Scans Pass | Snyk
Your scans came back clean, and the app is still exploitable. How chained risk forms across AI layers.
SentinelOne Aug 25
The Path to the Autonomous SOC: The Early Returns of AI & What It Means for Cybersecurity | SentinelOne
Discover how early-stage AI yields rapid SOC returns, driving platform consolidation and reducing analyst burnout in this blog post.
Unit 42 Aug 25
The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution
Explore Unit 42 research on AI-enabled malware. Learn how existing behavioral detection and endpoint analytics stop AI-authored code before execution.
Talos Intelligence Aug 25
The safety penalty: Reclaiming operational sovereignty in the age of AI
As frontier AI models become increasingly restrictive, security teams are facing a "safety penalty" that hampers real-time incident response. Discover how organizations can move toward operational sovereignty to ensure their defensive AI keeps pace with unconstrained adversaries.
Elastic Security Labs Aug 25
Agentic SOC alert triage: 60% to 92% AI accuracy — Elastic Security Labs
Inside the agentic SOC Elastic's InfoSec team runs in production: the three-agent pipeline, the analyst feedback loop, and the one-button close in Slack.
SecurityWeek Aug 24
Rethinking Application Security for the AI Era
As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk.
Industrial Cyber Aug 24
UK NCSC calls for risk-based controls as organizations deploy increasingly autonomous AI agents - Industrial Cyber
U.K. NCSC calls for risk-based controls as organizations deploy increasingly autonomous AI agents across complex workflows.
The Register Security Aug 22
If you're not using AI to attack your own systems, your adversaries will
Agents are also the new attack surface - cue defenders' existential angst
Part of the PlainSec briefing for 2026-08-25
Editions Related stories