Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft
Brief
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for remote code execution, credential theft, and cryptomining. AI infrastructure is now a cloud entry point.
Over 90 days, attackers tailored techniques for services routing model traffic and connecting agents to tools. Campaigns paired exposed-server flaws with instructions that push agents to run commands and seek API keys.
Researchers at Wiz. io identified sustained activity through honeypots mimicking AI services. They covered LiteLLM, MCP servers, LangChain, Flowise, Langflow, OpenWebUI, and Node-RED, showing tailored intrusion methods.
Wiz. io said in a report shared with Cyber Security News (CSN) that the impact can extend beyond one compromised application. AI proxies may centralize keys and cloud permissions.
