Critical RCE, Prompt Injection in AI Infrastructure Expose API Keys
Key Takeaways Cyberattackers are actively exploiting vulnerabilities in AI infrastructure, leveraging exposed gateways and agent tools to achieve remote code execution (RCE), steal credentials, and...
Key Takeaways
- Cyberattackers are actively exploiting vulnerabilities in AI infrastructure, leveraging exposed gateways and agent tools to achieve remote code execution (RCE), steal credentials, and deploy cryptominers.
- The campaigns specifically targeted popular AI frameworks and services including LiteLLM, MCP servers, LangChain, Flowise, Langflow, OpenWebUI, and Node-RED.
- Key vulnerabilities exploited include authentication bypass (CVE-2026-59822) and command injection (CVE-2026-42271) in LiteLLM/MCP, which can be chained with a Starlette host-header bypass (CVE-2026-48710) for unauthenticated RCE.
- Attackers utilize prompt injection techniques to instruct AI agents with shell access to execute malicious commands, often retrieving payloads from platforms like Pastebin.
- Compromised AI gateways can serve as central points for exfiltrating API keys and cloud permissions, enabling broader access to organizational data and paid AI model usage.
Cybersecurity researchers have uncovered widespread and targeted attacks against artificial intelligence (AI) infrastructure, demonstrating how threat actors are adapting their techniques to compromise these nascent systems. Over a 90-day period, attackers honed their methods to exploit vulnerabilities in AI services that manage model traffic and connect agents to various tools, ultimately achieving remote code execution (RCE), credential theft, and cryptomining operations. This emerging threat landscape positions AI infrastructure as a critical new entry point into cloud environments.
Security firm Wiz.io identified this sustained malicious activity through a network of honeypots designed to emulate common AI services. Their investigation revealed tailored intrusion techniques against a range of platforms, including LiteLLM, Model Context Protocol (MCP) servers, LangChain, Flowise, Langflow, OpenWebUI, and Node-RED.
According to Wiz.io’s report, shared with Cyber Security News (CSN), the ramifications of such compromises extend far beyond a single application. AI proxies frequently centralize API keys and cloud permissions, meaning a single, weakly secured deployment can act as a gateway to sensitive data, unauthorized use of paid AI models, and deeper internal systems.
Hackers Target AI Infrastructure With RCE
One notable campaign specifically focused on internet-exposed Model Context Protocol (MCP) services. MCP enables AI agents to interact with databases, code repositories, messaging platforms, and internal APIs. This broad connectivity significantly escalates the potential damage from a compromised gateway, as detailed in analyses of AI agent pipeline vulnerabilities.
Attackers successfully leveraged two critical flaws in LiteLLM: CVE-2026-59822, an authentication bypass in the MCP Gateway, and CVE-2026-42271, a command injection vulnerability in test endpoints. The authentication bypass allowed attackers to use a single-character bearer token to access critical MCP functions. For the command injection, threat actors crafted a malicious MCP server configuration that, when tested, launched a Python-based downloader and cryptominer, while returning a deceptive success message.
This <a href="https://ppl-ai-file-upload.s3.amazonaws.com/web/direct-files/attachments/11146061/caf262e9-f8dc-424e-84ef-2c7bf787623f/Hackers-Target-AI-Infrastructure-With-RCE-Prompt-Injection-and-API-Key-Theft.pdf?AWSAccessKeyId=ASIA2F3EMEYETPN2SVGQ&Signature=%2BTdXNgpvYoDmKD8PwJW9LCph1s4%3D&x-amz-security-token=IQoJb3JpZ2luX2VjEIj%2F%2F%2F%2F%2F%2F%2F%2F%2F%2FwEaCXVzLWVhc3QtMSJHMEUCIQDGsxZlQp9J71AtV%2BXB74qL7%2FJU%2FJmCRX7zNuJwMPiO7gIgARN4hvaW3D1c%2B1Aw06q0d74dG7byyEtlTGuWph85fwAq8wQIURABGgw2OTk3NTMzMDk3MDUiDCtyBxe1%2FV7ffEo87CrQBECMwR9H7Zr0GbyeqqylCPLPjhz4U4wX3jvGcjxk9WSh
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.