← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 27, 2026 · 10:23via CyberPress

Hackers Target LiteLLM, RAGFlow and Kestra AI Infrastructure to Steal API Keys and Mine Crypto

Brief

Hackers are increasingly targeting AI infrastructure to steal API keys, gain access to backend systems, maintain persistence, and mine cryptocurrency .

Microsoft has observed attacks against LiteLLM, RAGFlow, and Kestra three platforms that can hold sensitive model credentials, workflow permissions, database connections, and container access.

AI gateways, retrieval platforms, and workflow orchestration tools have become high-value targets because they sit between applications, users, data sources, and large language models.

A compromise can give attackers access to cloud credentials, provider API keys, internal services, and expensive computing resources.

Hackers Hit AI Infrastructure

In the LiteLLM case, attackers likely exploited an exposed gateway surface.

Read more on CyberPress