← Back to feed
PhishingEmerging1 sourceAug 26, 2026 · 16:43via Microsoft Security Blog

When AI infrastructure becomes the target: Securing gateways and control points

Brief

In this article

  • AI workloads are becoming high-value control points
  • Case study 1: LiteLLM gateway compromise
  • Case study 2: RAGFlow compromise
  • Case study 3: Kestra compromise
  • Mitigation and protection guidance
  • MITRE ATT&CK techniques observed
  • References
  • Learn more

AI is creating a new layer of enterprise infrastructure. Gateways, retrieval platforms, orchestration services, and containerized runtimes now sit between users, applications, data, and models. These systems concentrate credentials, data access, model connectivity, and execution privileges, making them some of the most powerful components in the AI stack.

That concentration of trust is also creating new opportunities for attackers. In recent investigations, Microsoft observed activity targeting three distinct AI workloads: a LiteLLM gateway, a RAGFlow deployment, and a Kestra workflow environment.

Read more on Microsoft Security Blog