AI Infrastructure Security: Securing Gateways and Control Points
Summary
Microsoft Security Research warns that AI gateways, retrieval platforms, and orchestration services are emerging as high-value attack targets. Based on observed compromises involving LiteLLM, RAGFlow, and Kestra, the report highlights how attackers are using these systems to steal secrets, gain persistence, and monetize compute—making stronger controls and monitoring essential for defenders.
Introduction
AI infrastructure is quickly becoming part of the enterprise control plane. Services such as model gateways, retrieval platforms, and workflow orchestrators often sit between users, apps, data, and AI models—meaning they can hold sensitive credentials, configuration data, and execution privileges. Microsoft’s latest research shows attackers are increasingly targeting these layers directly.
What Microsoft observed
Microsoft analyzed three separate compromises affecting AI-related workloads:
- LiteLLM gateway: Attackers likely exploited exposed gateway surfaces tied to public vulnerability chains, then harvested environment secrets, accessed database-related data, and deployed miner payloads.
- RAGFlow deployment: Activity included SSRF-style reconnaissance, code execution, and modifications designed to intercept newly configured LLM provider credentials.
- Kestra workflow environment: Attackers used workflow-origin shell execution, explored Docker and container environments, collected secrets, and monetized compute resources with XMRig.
Across all three cases, the attacker goals were similar:
- Steal credentials and API keys
- Establish persistence
- Access downstream systems and data
- Abuse compute resources for cryptomining
Why this matters for defenders
The key takeaway is that AI infrastructure now functions as a high-trust control point. A compromise in one of these services can expose:
- Model-provider API keys
- Database connection strings
- Tenant and routing configuration
- Workflow execution paths
- Container or host-level access
For IT and security teams, that means AI components should be treated like other critical enterprise infrastructure—not experimental side systems.
Recommended actions
Microsoft’s guidance points to several immediate steps:
- Inventory exposed AI management surfaces across gateways, orchestration tools, and retrieval services.
- Restrict administrative access using least privilege and network segmentation.
- Monitor for gateway-originated execution and unusual shell, Python, or container activity.
- Protect secrets by reducing reliance on environment variables where possible and rotating exposed credentials quickly.
- Patch vulnerable platforms and review public CVEs affecting exposed AI services.
- Watch for secret access and outbound exfiltration from AI runtime contexts.
Next steps
Organizations deploying AI services should review whether gateways and orchestration layers are internet-exposed, overprivileged, or lightly monitored. If your team uses LiteLLM, RAGFlow, Kestra, or similar tooling, now is a good time to validate patch levels, audit credential storage, and strengthen detection for suspicious activity originating from AI workloads.
Need help with Security?
Our experts can help you implement and optimize your Microsoft solutions.
Talk to an ExpertStay updated on Microsoft technologies