{"data":{"id":"bb81cbb4-61b3-4d71-b901-6b93d9965b3a","title":" Inside 90 days of attacks on AI infrastructure","summary":"Researchers at Wiz found widespread attacks on AI infrastructure services like LiteLLM and Flowise over 90 days, exploiting three main patterns: remote code execution (running unauthorized commands on systems) through exposed MCP servers (tools that let AI agents access external services like databases), prompt injection (tricking AI agents by hiding malicious instructions in their inputs), and post-exploitation techniques targeting AI-specific systems. AI infrastructure is attractive to attackers because it often concentrates many API credentials (keys for services like OpenAI and Azure) in one place, and AI agents are designed to execute instructions from external inputs, making them vulnerable to compromise.","solution":"The source documents two specific vulnerabilities in LiteLLM but does not provide explicit mitigation steps or patches. It references CVE-2026-59822 (an OAuth2 authentication flaw in the MCP Gateway) and CVE-2026-42271 (command injection in MCP server test endpoints), noting that CVE-2026-42271 was added to the CISA KEV (Known Exploited Vulnerabilities list) in June 2026, but no version updates or fix instructions are mentioned in the text.","labels":["security","research"],"sourceUrl":"https://www.wiz.io/blog/ai-infrastructure-honeypot","publishedAt":"2026-08-27T16:33:16.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"high","attackType":["supply_chain","prompt_injection","model_poisoning"],"issueType":"news","affectedPackages":null,"affectedVendors":["LangChain"],"affectedVendorsRaw":["LiteLLM","Flowise","LangChain","Langflow","ChromaDB","Ollama","OpenAI","Anthropic","Azure","Gemini"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"patchAvailable":null,"disclosureDate":"2026-08-27T16:33:16.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"advanced","impactType":["confidentiality","integrity","availability"],"aiComponentTargeted":"framework","llmSpecific":false,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":null}}