Recent investigations by Microsoft have revealed a concerning trend in the cybersecurity landscape, where AI infrastructure is increasingly becoming a target for cybercriminals. Specifically, attackers have focused on three distinct AI workloads: LiteLLM, RAGFlow, and Kestra. These intrusions have been characterized by credential theft, the establishment of persistence mechanisms, and the monetization of compromised compute resources. The findings highlight the need for organizations to enhance their security measures around these critical AI systems, which serve as gateways to sensitive data and operational capabilities. For more details, refer to the full report by Microsoft Security Research.
AI Workloads as High-Value Targets
The targeted AI workloads serve various functions but share common vulnerabilities that expose valuable assets, including model-provider keys and database connection strings. Microsoft emphasizes that as organizations deploy more AI systems, these platforms must receive the same level of security scrutiny as other critical infrastructure.
Observed Compromises
Microsoft’s analysis identified three main attack vectors:
- LiteLLM: Attackers exploited vulnerabilities in the LiteLLM gateway, leading to credential theft and backend database access.
- RAGFlow: The RAGFlow deployment was targeted through potential SSRF-style reconnaissance, allowing attackers to intercept LLM provider credentials.
- Kestra: The Kestra workflow environment was compromised, enabling attackers to execute shell commands and deploy cryptominers.
Impact and Recommendations
The compromises have resulted in significant risks, including the exposure of sensitive credentials and unauthorized access to compute resources. Microsoft recommends treating AI gateways as critical secrets stores, implementing strict access controls, and continuously monitoring for unusual activity. Organizations are urged to adopt a proactive approach to securing their AI infrastructure to mitigate these emerging threats.
Follow Cyber Warriors Middle East for further ransomware, cybercrime and DarkWatch developments.



