Cybersecurity News

Filters
Tag
Reset

Filtered by tag: llm infrastructure × Clear

Hackers Exploit AI Infrastructure to Steal API Keys, Gain Persistence and Mine Cryptocurrency

Matched: cryptocurrency

Microsoft research reveals hackers are targeting AI infrastructure — specifically LiteLLM, RAGFlow, and Kestra — to steal API keys, gain persistence, and mine cryptocurrency. Attackers exploited vulnerabilities and exposed endpoints to harvest credentials, install hidden hooks capturing provider keys, and run XMRig for Monero mining. Recommended mitigations include patching AI services, rotating credentials, restricting admin port access, and storing keys in managed secrets systems rather than environment variables.