Security

AI Infrastructure Security: Securing Gateways and Control Points

2 min read

Summary

Microsoft Security Research warns that AI gateways, retrieval platforms, and orchestration services are emerging as high-value attack targets. Based on observed compromises involving LiteLLM, RAGFlow, and Kestra, the report highlights how attackers are using these systems to steal secrets, gain persistence, and monetize compute—making stronger controls and monitoring essential for defenders.

Need help with Security?Talk to an Expert

Introduction

AI infrastructure is quickly becoming part of the enterprise control plane. Services such as model gateways, retrieval platforms, and workflow orchestrators often sit between users, apps, data, and AI models—meaning they can hold sensitive credentials, configuration data, and execution privileges. Microsoft’s latest research shows attackers are increasingly targeting these layers directly.

What Microsoft observed

Microsoft analyzed three separate compromises affecting AI-related workloads:

  • LiteLLM gateway: Attackers likely exploited exposed gateway surfaces tied to public vulnerability chains, then harvested environment secrets, accessed database-related data, and deployed miner payloads.
  • RAGFlow deployment: Activity included SSRF-style reconnaissance, code execution, and modifications designed to intercept newly configured LLM provider credentials.
  • Kestra workflow environment: Attackers used workflow-origin shell execution, explored Docker and container environments, collected secrets, and monetized compute resources with XMRig.

Across all three cases, the attacker goals were similar:

  • Steal credentials and API keys
  • Establish persistence
  • Access downstream systems and data
  • Abuse compute resources for cryptomining

Why this matters for defenders

The key takeaway is that AI infrastructure now functions as a high-trust control point. A compromise in one of these services can expose:

  • Model-provider API keys
  • Database connection strings
  • Tenant and routing configuration
  • Workflow execution paths
  • Container or host-level access

For IT and security teams, that means AI components should be treated like other critical enterprise infrastructure—not experimental side systems.

Microsoft’s guidance points to several immediate steps:

  • Inventory exposed AI management surfaces across gateways, orchestration tools, and retrieval services.
  • Restrict administrative access using least privilege and network segmentation.
  • Monitor for gateway-originated execution and unusual shell, Python, or container activity.
  • Protect secrets by reducing reliance on environment variables where possible and rotating exposed credentials quickly.
  • Patch vulnerable platforms and review public CVEs affecting exposed AI services.
  • Watch for secret access and outbound exfiltration from AI runtime contexts.

Next steps

Organizations deploying AI services should review whether gateways and orchestration layers are internet-exposed, overprivileged, or lightly monitored. If your team uses LiteLLM, RAGFlow, Kestra, or similar tooling, now is a good time to validate patch levels, audit credential storage, and strengthen detection for suspicious activity originating from AI workloads.

Need help with Security?

Our experts can help you implement and optimize your Microsoft solutions.

Talk to an Expert

Stay updated on Microsoft technologies

AI securityLiteLLMRAGFlowKestraMicrosoft Security

Related Posts

Security

Microsoft Digital Defense Report 2026: Key Security Insights

Microsoft's 2026 Digital Defense Report highlights how AI and growing system interconnectedness are reshaping both cyberattacks and defense strategies. The report emphasizes that organizations must secure AI, identities, data, and cloud environments together while improving signal correlation across tools to detect modern threats faster.

Security

Government Cyber Risk in 2026: Microsoft’s 5 Priorities

Microsoft says government agencies were the most targeted sector in 2026, accounting for 27% of observed cyber threat activity. The company urges public-sector leaders to focus on five resilience priorities, including faster response, AI security, bidirectional information sharing, and planning for incidents that spread across suppliers and essential services.

Security

Microsoft Ignite 2026 Security Guide: Key Sessions

Microsoft has published its security guide for Microsoft Ignite 2026, highlighting AI-first security themes, a dedicated Security Pre-Day, and technical sessions focused on securing identities, data, devices, clouds, and AI agents. For IT and security teams, the event offers an early look at Microsoft’s roadmap and practical guidance for building an AI-ready security strategy.

Security

CVE-2026-73570: Zimbra Mail Server Exploitation

Microsoft is tracking active exploitation of CVE-2026-73570, an unauthenticated command injection flaw affecting internet-facing Zimbra mail servers with the optional zimbra-snmp package installed and SNMP notifications enabled. The issue can lead to web shell deployment, privilege escalation, mailbox data theft, and persistent remote access, making immediate patching and configuration review critical for administrators.

Security

Phishing Abuses RMM Tools for Persistent Access

Microsoft security researchers observed phishing campaigns in July 2026 that used a legitimate MSP360 RMM installer disguised as meeting invites, PDF updates, and other lures to gain remote access. Attackers then deployed ConnectWise ScreenConnect for redundant persistence, highlighting the need for tighter controls on remote management tools and better detection of unapproved RMM activity.

Security

Azure DevOps Attack Path Exposed in New DART Report

Microsoft’s latest DART cyberattack report shows how a single compromised identity was used to access Azure DevOps, alter pipelines, and harvest Kubernetes credentials. The case highlights how tightly connected identity, DevOps, and cloud environments can let attackers move far beyond source code, making stronger identity and pipeline controls essential.