Executive Summary

CISA added seven critical vulnerabilities to its Known Exploited Vulnerabilities catalog in September 2026 after observing active exploitation by threat actors. The vulnerabilities span multiple platforms including SonicWall SMA appliances, Sangoma Switchvox, JFrog Artifactory, and AI infrastructure components like LiteLLM and Kestra. Attackers exploited these flaws to deploy reverse shells, cryptocurrency miners, and conduct unauthorized operations, with campaigns targeting AI infrastructure becoming increasingly prominent as adversaries seek to harvest API keys and monetize compromised systems.

This incident highlights the growing threat landscape targeting AI infrastructure and the critical importance of rapid vulnerability remediation. With AI systems becoming prime targets for credential theft and resource hijacking, organizations must prioritize security updates and implement comprehensive monitoring across their AI workloads to prevent similar exploitation campaigns.

Why This Matters Now

AI infrastructure has emerged as a lucrative target for cybercriminals seeking to steal API keys, deploy cryptocurrency miners, and gain persistent access to backend systems, making immediate patching and enhanced monitoring of AI workloads critical for organizational security.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

AI infrastructure components like LiteLLM and Kestra often contain valuable API keys and have direct access to backend systems, making them attractive targets for credential theft and persistent access establishment.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would have significantly constrained this multi-vector attack on AI infrastructure by limiting lateral movement between compromised systems and reducing the attackers' ability to establish widespread persistent access across the environment.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: While initial compromise may still occur through vulnerable applications, Zero Trust segmentation would likely constrain the attackers' ability to immediately access surrounding infrastructure and AI workloads from the initially compromised appliances.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Administrative token abuse would likely face significant constraints as Zero Trust segmentation limits the scope of elevated privileges, reducing the attackers' ability to gain broad administrative access across multiple AI infrastructure components.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Lateral movement through Docker environments and database access would likely be significantly constrained by east-west traffic controls, reducing the attackers' ability to pivot freely between AI workloads and supporting infrastructure components.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Command and control establishment would likely face constraints through comprehensive traffic visibility and control mechanisms, reducing the attackers' ability to maintain persistent communication channels across the distributed AI infrastructure environment.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Data exfiltration attempts would likely be constrained by egress security controls that limit outbound data flows from AI workloads, reducing the attackers' ability to transfer harvested API keys and model configurations to external systems.

Impact (Mitigations)

While some cryptocurrency mining activity may still occur on initially compromised systems, the overall resource impact would likely be constrained to isolated workload segments rather than spreading across the entire AI infrastructure environment.

Impact at a Glance

Affected Business Functions

  • AI/ML Model Operations
  • API Gateway Services
  • Network Security Infrastructure
  • Database Management Systems
Operational Disruption

Estimated downtime: 7 days

Financial Impact

Estimated loss: $2,500,000

Data Exposure

AI model configurations, API keys, authentication tokens, database credentials, LLM provider keys, user authentication data, and proprietary AI workflows. Cryptocurrency mining operations consuming computational resources across multiple infrastructure platforms.

Recommended Actions

  • Implement Zero Trust Segmentation with identity-based policies to prevent lateral movement between AI workloads and limit blast radius of initial compromises
  • Deploy Egress Security & Policy Enforcement to block unauthorized cryptocurrency mining traffic and prevent exfiltration of API keys to external destinations
  • Enable Multicloud Visibility & Control to detect anomalous interactions with AI infrastructure including repeated malformed requests and suspicious automation patterns
  • Utilize Threat Detection & Anomaly Response capabilities to identify covert remote access tools and baseline normal AI workload behavior for deviation detection
  • Apply Inline IPS (Suricata) to inspect traffic for known exploit patterns targeting AI infrastructure vulnerabilities and block malicious payloads before execution

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image