When AI infrastructure becomes the target: Securing gateways and control points

    Date: 08/27/2026

    Severity: High

    Summary

    Researchers highlight attacks targeting exposed AI infrastructure, including LiteLLM, RAGFlow, and Kestra, where adversaries exploited AI gateways and orchestration platforms for credential theft, remote code execution, persistence, container discovery, and cryptomining. The campaign also demonstrates risks to cloud-based AI workloads, with vulnerabilities such as CVE-2026-42271, CVE-2026-48710, and CVE-2026-49869 enabling attackers to compromise exposed services and access sensitive cloud resources. The research emphasizes securing AI gateways, restricting administrative access, protecting secrets, and monitoring cloud and container environments for suspicious activity. 

    Indicators of Compromise (IOC) List

    Domain/URLs

    45.150.109.151.sslip.io

    auto.c3pool.org

    gobygo.net

    oast.fun

    oast.me

    oast.pro

    yosemite.jp

    IP Address

    135.125.10.56

    172.232.38.92

    194.213.18.133

    45.150.109.151

    47.86.197.116

    Hash

    3af9f25a4d45bb4f1ec5627cdbc6703cf3b4be75a892162d299d80ddfb266f42

    3d24ac736635e0fa0c5c459c9e18ca09d1ec9a1751a4503130934395609bd7e0

    49fdcf32bfe837899a84e8938f0d07ae96ddd218a280a09eb60df8d64597bd8f

    f64b88e9318bdf23f2dd119a0ce1dd1bdb3c8cd2e0e1e23ba3ef2e19072b79cc

    Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection

    Detection Query 1 :

    domainname like "auto.c3pool.org" or url like "auto.c3pool.org" or siteurl like "auto.c3pool.org" or domainname like "yosemite.jp" or url like "yosemite.jp" or siteurl like "yosemite.jp" or domainname like "oast.me" or url like "oast.me" or siteurl like "oast.me" or domainname like "45.150.109.151.sslip.io" or url like "45.150.109.151.sslip.io" or siteurl like "45.150.109.151.sslip.io" or domainname like "oast.pro" or url like "oast.pro" or siteurl like "oast.pro" or domainname like "oast.fun" or url like "oast.fun" or siteurl like "oast.fun" or domainname like "gobygo.net" or url like "gobygo.net" or siteurl like "gobygo.net"

    Detection Query 2 :

    dstipaddress IN ("135.125.10.56","194.213.18.133","45.150.109.151","172.232.38.92","47.86.197.116") or srcipaddress IN ("135.125.10.56","194.213.18.133","45.150.109.151","172.232.38.92","47.86.197.116")

    Detection Query 3 :

    sha256hash IN ("3af9f25a4d45bb4f1ec5627cdbc6703cf3b4be75a892162d299d80ddfb266f42","3d24ac736635e0fa0c5c459c9e18ca09d1ec9a1751a4503130934395609bd7e0","49fdcf32bfe837899a84e8938f0d07ae96ddd218a280a09eb60df8d64597bd8f","f64b88e9318bdf23f2dd119a0ce1dd1bdb3c8cd2e0e1e23ba3ef2e19072b79cc")

    Reference: 

    https://www.microsoft.com/en-us/security/blog/2026/08/26/when-ai-infrastructure-becomes-target-securing-gateways-control-points/            


    Tags

    MalwareVulnerabilitiesExploitAICredential HarvestingRCECryptominingCVE-2026Cloud InfrastructureLLMs

    « Previous ArticleNext Article »

    Comments

    No records to display

    Looking for Something?
    Threat Research Categories:
    Tags