AI Infrastructure Under Attack: Microsoft Warns of Increasing Threats to AI Systems
A new threat is emerging in the world of artificial intelligence (AI), as attackers target AI infrastructure to steal credentials, establish persistence, and monetize compromised compute resources. Microsoft has observed activity targeting three distinct AI workloads: a LiteLLM gateway, a RAGFlow deployment, and a Kestra workflow environment.
The intrusion paths varied, but the objectives were strikingly similar. Attackers sought to steal credentials, establish persistence, and monetize compromised compute resources. The concentration of trust in these systems makes them high-value targets that deserve the same security scrutiny as other critical enterprise infrastructure.
Micro- soft observed three compromises across AI workloads: LiteLLM, RAGFlow, and Kestra. In each case, attackers used different techniques to achieve their objectives, but the broader pattern is clear: attackers treat AI infrastructure as a control plane where credential theft, host compromise, and downstream data access can converge.
To mitigate these threats, defenders should inventory exposed AI management surfaces, restrict administrative access, and monitor for gateway-originated execution and secret access. By taking these steps, organizations can reduce the risk of attack and protect their valuable assets.