Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hackers Use AI Systems for Cyber Attacks and Cryptocurrency Mining

Hackers Use AI Systems for Cyber Attacks and Cryptocurrency Mining

Posted on August 27, 2026 By CWS

Introduction to AI Cyber Exploitation

A recent study by Microsoft reveals a growing trend where cybercriminals leverage AI infrastructures to breach corporate systems. These exposed AI platforms, which include gateways, retrieval tools, and workflow services, are being exploited to access provider credentials, databases, and computing resources. This report underscores a worrying shift in hacker tactics targeting the backbone of AI systems rather than conventional endpoints or cloud services.

The study highlights three main targets: LiteLLM, RAGFlow, and Kestra. Despite different entry points, attackers consistently pursue a strategy that involves stealing sensitive information, maintaining access, and using compromised servers for illicit activities like cryptocurrency mining. This marks a significant evolution in cyber attack patterns, emphasizing the need for enhanced security measures in AI and cloud environments.

Intrusion Tactics and Vulnerabilities

Microsoft’s findings indicate that attackers exploit vulnerabilities in AI systems, as seen in the LiteLLM case. Here, the attackers likely accessed the system through a gateway vulnerability, identified as CVE-2026-42271 and CVE-2026-48710. This led to the extraction of API keys, tokens, and database credentials, which were then sent to the attackers, ensuring fallback options in case of blocked routes.

Similar methods were used in other cases. For instance, RAGFlow experienced server-side request probing, followed by code execution and the insertion of a Python hook in the application’s configuration. This allowed attackers to capture API keys and other critical data discreetly whenever an administrator configured a provider.

Persistence and Cryptocurrency Mining

The Kestra incident further exemplifies these tactics. Attackers exploited a critical authentication bypass flaw, CVE-2026-49869, to execute malicious workflows. They manipulated Docker environments and utilized victim systems to mine Monero cryptocurrency, demonstrating how attackers can persistently exploit compromised systems.

Persistence was achieved through various techniques, including altering service-account SSH keys, manipulating cron jobs, and creating hidden relays. These methods complicate efforts to clean up intrusions and highlight the challenges security teams face in protecting AI infrastructures from sustained attacks.

Security Recommendations and Future Outlook

To combat these threats, Microsoft recommends immediate patching of exposed AI services and rotating keys associated with vulnerable gateways. It’s crucial to monitor database activities and provider accounts for any unusual behavior. Organizations should enforce strict authentication protocols, keep administrative interfaces off public networks, and use managed secret systems to store API keys.

Furthermore, logging network activities such as DNS callbacks and unauthorized process executions can help detect and mitigate attacks early. By implementing these security measures, companies can better protect their AI infrastructures and prevent costly breaches and misuse of resources.

Moving forward, as AI technology continues to evolve, so too must the strategies to safeguard against cyber threats. Vigilance and proactive security measures are essential in preventing future incidents and ensuring the integrity of AI systems.

Cyber Security News Tags:AI exploitation, API security, authentication bypass, cloud security, container environments, cryptocurrency mining, Cybersecurity, data breaches, data protection, hacking tactics, infrastructure vulnerabilities, Microsoft research, network security, secret management, threat mitigation

Post navigation

Previous Post: Okta’s Earnings Jump as AI Security Demand Grows
Next Post: Amazon Kiro Vulnerability Risks Data Exposure

Related Posts

Widespread SonicWall Firewall Attacks Exploiting Vulnerabilities Widespread SonicWall Firewall Attacks Exploiting Vulnerabilities Cyber Security News
Tego AI Exposes Potential Risks in Claude Tag Integration Tego AI Exposes Potential Risks in Claude Tag Integration Cyber Security News
5 Best IT Infrastructure Modernisation Services In 2025 5 Best IT Infrastructure Modernisation Services In 2025 Cyber Security News
Cybercriminals Exploit Proxifier to Spread Crypto Malware Cybercriminals Exploit Proxifier to Spread Crypto Malware Cyber Security News
Adform’s Ad Platform Breached to Distribute Crypto Malware Adform’s Ad Platform Breached to Distribute Crypto Malware Cyber Security News
CISA Chief Uploaded Sensitive Documents into Public ChatGPT CISA Chief Uploaded Sensitive Documents into Public ChatGPT Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Australian Duo Arrested for Massive TeamPCP Cyber Attacks
  • Executive Order to Secure US Power Grid from Foreign Threats
  • Amazon Kiro Vulnerability Risks Data Exposure
  • Hackers Use AI Systems for Cyber Attacks and Cryptocurrency Mining
  • Okta’s Earnings Jump as AI Security Demand Grows

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Australian Duo Arrested for Massive TeamPCP Cyber Attacks
  • Executive Order to Secure US Power Grid from Foreign Threats
  • Amazon Kiro Vulnerability Risks Data Exposure
  • Hackers Use AI Systems for Cyber Attacks and Cryptocurrency Mining
  • Okta’s Earnings Jump as AI Security Demand Grows

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark