Microsoft observed intrusions targeting exposed LiteLLM, RAGFlow, and Kestra AI control-plane workloads to obtain credentials, establish persistence, access downstream data, and deploy cryptocurrency-mining tools. In the LiteLLM case, attackers likely exploited an exposed gateway, harvested runtime and PostgreSQL secrets, deployed XMRig-like tooling, and persisted through SSH keys, cron modifications, hidden files, and immutable file attributes.
In a RAGFlow environment, attackers conducted SSRF-style reconnaissance and modified the application to persistently intercept newly configured LLM-provider credentials; Microsoft did not confirm the code-execution vulnerability used. A Kestra intrusion was assessed as likely exploiting CVE-2026-49869 to bypass authentication, run malicious workflows, access Docker container environments, deploy XMRig, and collect data through Kestra's key-value interface. Microsoft advised treating AI gateways, retrieval platforms, and workflow orchestrators as critical control-plane infrastructure because they centralize privileged execution and high-value secrets.

Track how attackers are adapting to this technology.
4 events from the most recent confirmed update back to the earliest known activity.
Researchers reported that the campaign targeting exposed LiteLLM, RAGFlow, and Kestra services leveraged CVE-2026-42271, CVE-2026-48710, and CVE-2026-49869. The report also published associated domains, IP addresses, and SHA-256 indicators linked to the activity.
Microsoft assessed with high confidence that attackers likely exploited CVE-2026-49869 to bypass Kestra authentication, create a malicious workflow, and obtain worker-side shell execution. They accessed the Docker socket and container environment data, deployed XMRig connected to a Monero mining pool, and later collected data through Kestra's key-value interface.
Microsoft observed an intrusion of an exposed RAGFlow application, preceded by SSRF-style reconnaissance and followed by code execution in the service context. Attackers installed a hidden Python hook that intercepted and exfiltrated newly configured LLM-provider credentials and endpoint metadata.
Microsoft observed an intrusion of an exposed LiteLLM gateway, likely through exploitation of its gateway surface. The attackers harvested runtime and PostgreSQL credentials, accessed the backing Azure Database for PostgreSQL, deployed XMRig-like mining tooling, and established multiple persistence mechanisms.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 18 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
6 references tracked. Mallory keeps watching after this page renders.
community.gurucul.com
Open sourcecybersecuritynews.com
Open sourcemalware.news
Open sourcemicrosoft.com
Open sourcecve.org
Open sourcelearn.microsoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.