ZeroHour
Wiz Blogpublished ()ingested Yaara Shriki

Inside 90 days of attacks on AI infrastructure

mediumAI safety & security exploited in the wildimportance 62
AI summary · glm-5.3-flash

Wiz honeypots recorded 90 days of active campaigns attacking LiteLLM, MCP servers, and AI frameworks via RCE, blind prompt injection, and credential theft.

Wiz deployed AI infrastructure honeypots and observed active attack campaigns over a 90-day window. Attackers targeted LiteLLM, MCP servers, and popular AI frameworks using techniques including remote code execution, blind prompt injection, and memory credential theft. The findings show exposed AI infrastructure is being actively targeted in the wild.

  • Honeypots captured active campaigns across 90 days of observation.
  • LiteLLM and MCP servers were targeted attack surfaces.
  • Techniques included RCE, blind prompt injection, and memory credential theft.
  • Highlights exposure risk of internet-facing AI infrastructure.
VendorsWiz
ProductsLiteLLMMCP
Full article

Wiz honeypots uncover active campaigns targeting LiteLLM, MCP servers, and AI frameworks through RCE, blind prompt injection, and memory credential theft.

This source does not provide full text. Read it at wiz.io.