Wiz Threat Research deployed honeypots across AI and ML services including LiteLLM, Flowise, LangChain, Langflow, ChromaDB, and Ollama, observing sustained attack activity over 90 days. Three distinct attack patterns emerged: exploitation of Internet-facing MCP servers for remote code execution through authentication bypass and command injection vulnerabilities; blind prompt injection attacks against AI agent frameworks using out-of-band DNS callbacks to confirm execution; and AI-native post-exploitation techniques adapted to AI infrastructure internals, including extracting master keys from Python module state and staging cryptominers in framework-specific directories. Attackers demonstrated deep knowledge of AI tooling internals, targeting credential concentration points where proxies hold multiple provider keys, and exploiting agent reachability to execute instructions embedded in requests. The campaigns primarily deployed XMRig cryptominers, leveraging framework-specific paths and processes for camoufl...
Created: 2026-08-28
類似するPulseは見つかりませんでした。
事実ベースの脅威アクターは見つかりませんでした。
推論ベースの脅威アクターは見つかりませんでした。
このPulseに見つかったCVEはありません。