Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Hackers Use AI Systems for Cyber Attacks and Cryptocurrency Mining

Hackers Use AI Systems for Cyber Attacks and Cryptocurrency Mining

Posted on August 27, 2026 By CWS

Introduction to AI Cyber Exploitation

A recent study by Microsoft reveals a growing trend where cybercriminals leverage AI infrastructures to breach corporate systems. These exposed AI platforms, which include gateways, retrieval tools, and workflow services, are being exploited to access provider credentials, databases, and computing resources. This report underscores a worrying shift in hacker tactics targeting the backbone of AI systems rather than conventional endpoints or cloud services.

The study highlights three main targets: LiteLLM, RAGFlow, and Kestra. Despite different entry points, attackers consistently pursue a strategy that involves stealing sensitive information, maintaining access, and using compromised servers for illicit activities like cryptocurrency mining. This marks a significant evolution in cyber attack patterns, emphasizing the need for enhanced security measures in AI and cloud environments.

Intrusion Tactics and Vulnerabilities

Microsoft’s findings indicate that attackers exploit vulnerabilities in AI systems, as seen in the LiteLLM case. Here, the attackers likely accessed the system through a gateway vulnerability, identified as CVE-2026-42271 and CVE-2026-48710. This led to the extraction of API keys, tokens, and database credentials, which were then sent to the attackers, ensuring fallback options in case of blocked routes.

Similar methods were used in other cases. For instance, RAGFlow experienced server-side request probing, followed by code execution and the insertion of a Python hook in the application’s configuration. This allowed attackers to capture API keys and other critical data discreetly whenever an administrator configured a provider.

Persistence and Cryptocurrency Mining

The Kestra incident further exemplifies these tactics. Attackers exploited a critical authentication bypass flaw, CVE-2026-49869, to execute malicious workflows. They manipulated Docker environments and utilized victim systems to mine Monero cryptocurrency, demonstrating how attackers can persistently exploit compromised systems.

Persistence was achieved through various techniques, including altering service-account SSH keys, manipulating cron jobs, and creating hidden relays. These methods complicate efforts to clean up intrusions and highlight the challenges security teams face in protecting AI infrastructures from sustained attacks.

Security Recommendations and Future Outlook

To combat these threats, Microsoft recommends immediate patching of exposed AI services and rotating keys associated with vulnerable gateways. It’s crucial to monitor database activities and provider accounts for any unusual behavior. Organizations should enforce strict authentication protocols, keep administrative interfaces off public networks, and use managed secret systems to store API keys.

Furthermore, logging network activities such as DNS callbacks and unauthorized process executions can help detect and mitigate attacks early. By implementing these security measures, companies can better protect their AI infrastructures and prevent costly breaches and misuse of resources.

Moving forward, as AI technology continues to evolve, so too must the strategies to safeguard against cyber threats. Vigilance and proactive security measures are essential in preventing future incidents and ensuring the integrity of AI systems.

Cyber Security News Tags:AI exploitation, API security, authentication bypass, cloud security, container environments, cryptocurrency mining, Cybersecurity, data breaches, data protection, hacking tactics, infrastructure vulnerabilities, Microsoft research, network security, secret management, threat mitigation

Post navigation

Previous Post: Okta’s Earnings Jump as AI Security Demand Grows
Next Post: Amazon Kiro Vulnerability Risks Data Exposure

Related Posts

New Attack Technique Tricks AI Browsers Using a Simple ‘#’ New Attack Technique Tricks AI Browsers Using a Simple ‘#’ Cyber Security News
Microsoft Warns Secure Boot May Be Bypassed as Windows UEFI Certificates Expire Microsoft Warns Secure Boot May Be Bypassed as Windows UEFI Certificates Expire Cyber Security News
Critical FortiClient EMS Vulnerabilities Expose 2,000 Servers Critical FortiClient EMS Vulnerabilities Expose 2,000 Servers Cyber Security News
Multiple Splunk Enterprise Vulnerabilities Let Attackers Execute Unauthorized JavaScript code Multiple Splunk Enterprise Vulnerabilities Let Attackers Execute Unauthorized JavaScript code Cyber Security News
North Korean Hackers Exploit Novel Malware for Air-Gapped Systems North Korean Hackers Exploit Novel Malware for Air-Gapped Systems Cyber Security News
Threat Actors Claim Breach Of Huawei Technologies Source Code and Internal Tools Threat Actors Claim Breach Of Huawei Technologies Source Code and Internal Tools Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Executive Order to Secure US Power Grid from Foreign Threats
  • Amazon Kiro Vulnerability Risks Data Exposure
  • Hackers Use AI Systems for Cyber Attacks and Cryptocurrency Mining
  • Okta’s Earnings Jump as AI Security Demand Grows
  • Australian Duo Charged in Global Cybercrime Operation

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Executive Order to Secure US Power Grid from Foreign Threats
  • Amazon Kiro Vulnerability Risks Data Exposure
  • Hackers Use AI Systems for Cyber Attacks and Cryptocurrency Mining
  • Okta’s Earnings Jump as AI Security Demand Grows
  • Australian Duo Charged in Global Cybercrime Operation

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark