When AI infrastructure becomes the target: Securing gateways and control points
AI Infrastructure Under Siege: Microsoft Warns of Rising Cyber Threats Targeting AI Gateways in Malaysia
Source: Microsoft Security Blog · August 26, 2026 at 10:01 PM · AI-assisted report
Single-sourceKUALA LUMPUR, 27 AUGUST 2026 —
AI Infrastructure Under Siege: Microsoft Warns of Rising Cyber Threats Targeting AI Gateways in Malaysia
Market Impact
KUALA LUMPUR, Aug 26 — Microsoft’s threat intelligence team has uncovered a surge in cyberattacks targeting exposed AI infrastructure, including vulnerabilities in gateways like LiteLLM, which are increasingly becoming high-value targets for credential theft, cryptomining, and data exfiltration. In a detailed report published on Microsoft’s Security Blog, researchers highlighted three distinct intrusion campaigns—exploiting LiteLLM gateways, RAGFlow deployments, and Kestra workflow environments—where attackers leveraged AI control planes to gain persistent access and monetize compromised resources.
AI infrastructure now forms a critical layer in enterprise systems, with gateways, retrieval platforms, and orchestration services acting as intermediaries between users, applications, and AI models. These components centralize credentials, data access, and execution privileges, making them prime targets for cybercriminals. Microsoft’s investigation revealed that attackers consistently pursued three objectives: harvesting credentials, establishing persistence, and abusing compute power for cryptomining. The pattern underscores a broader shift where AI systems are treated as control planes, enabling multi-stage attacks that converge on credential theft and downstream data access.
The most detailed case involved a LiteLLM gateway, a proxy service commonly deployed to manage interactions between applications and AI model providers. Microsoft assessed with high confidence that initial access was gained through exploitation of exposed LiteLLM surfaces, likely via a chained attack leveraging CVE-2026-42271—a command-execution flaw in LiteLLM’s MCP stdio test endpoints—and CVE-2026-48710, a Starlette host-header validation bypass that could allow unauthenticated remote code execution. Once inside, attackers executed a six-stage attack chain: harvesting credentials (including model-provider API keys and database connection strings), delivering payloads via masqueraded ELF binaries, conducting host reconnaissance, deploying cryptomining tools (XMRig), accessing the LiteLLM-backed PostgreSQL database to extract model and virtual-key records, and establishing persistent backdoor access through service-account modifications and hidden file execution.
Malaysia’s growing adoption of AI-driven enterprise solutions—particularly in sectors such as finance, healthcare, and logistics—could amplify exposure to such threats. Organizations relying on AI gateways or cloud-based AI services may face elevated risks if these systems are not properly secured. The LiteLLM compromise demonstrated how a single gateway breach could lead to cascading impacts: exposure of upstream model keys, proxy-issued virtual keys, and sensitive database configurations. For Malaysian enterprises, this highlights the need to treat AI infrastructure with the same rigor as traditional critical systems, including inventorying exposed management surfaces, enforcing least-privilege access, and monitoring for anomalous execution originating from AI gateways.
The report also flagged vulnerabilities in RAGFlow, a platform used for document processing and retrieval-augmented generation (RAG), which stores tenant LLM configurations and processes provider credentials. While Microsoft could not definitively attribute the observed intrusion to a specific flaw, it noted that publicly documented issues—such as CVE-2026-45312 (Jinja2 server-side template injection) and CVE-2026-24770 (path traversal leading to arbitrary file overwrite)—could provide plausible entry points. These findings suggest that even specialized AI tools are not immune to exploitation, particularly when deployed in internet-facing configurations.
Looking ahead, Microsoft warns that as AI adoption accelerates, attackers will continue to refine tactics targeting AI control planes. The convergence of credential theft, cryptomining, and data exfiltration in a single attack chain signals a maturing threat landscape. For Malaysian businesses, the implications are clear: robust monitoring of AI gateway traffic, strict access controls, and rapid patching of known vulnerabilities are essential to mitigate risks. The report serves as a timely reminder that securing AI infrastructure is no longer optional—it is a strategic imperative in an era where AI systems are both business enablers and potential attack vectors.
Related: Microsoft · Kuala Lumpur