Cybersecurity News
Filters
Filtered by tag: ai security × Clear
Hackers Exploit AI Infrastructure to Steal API Keys, Gain Persistence and Mine Cryptocurrency
Matched: cryptocurrency
Microsoft research reveals hackers are targeting AI infrastructure — specifically LiteLLM, RAGFlow, and Kestra — to steal API keys, gain persistence, and mine cryptocurrency. Attackers exploited vulnerabilities and exposed endpoints to harvest credentials, install hidden hooks capturing provider keys, and run XMRig for Monero mining. Recommended mitigations include patching AI services, rotating credentials, restricting admin port access, and storing keys in managed secrets systems rather than environment variables.
Why most organizations are getting AI security wrong (and why it’s about to catch up with them)
Organizations are deploying AI rapidly without adequate security frameworks, creating dangerous gaps. Unlike traditional applications, AI operates as a dynamic chain of events — prompts, model responses, agent actions, data retrieval — where risks exist throughout, not at single points. Traditional security tools sit around AI rather than within it, reacting after the fact. Security decisions trail behind innovation teams, and bolt-on tools fail to address AI's cross-cutting nature. Effective AI security requires embedding controls directly into execution paths, particularly traffic flows where requests and responses are processed.
