<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Ai-Infrastructure on CuraSec</title><link>https://curasec.metacog.co.kr/tags/ai-infrastructure/</link><description>Recent content in Ai-Infrastructure on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Thu, 27 Aug 2026 21:01:55 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/ai-infrastructure/index.xml" rel="self" type="application/rss+xml"/><item><title>Microsoft TI: LiteLLM gateways actively exploited for cred theft and cryptomining</title><link>https://curasec.metacog.co.kr/insights/2026-08-27-when-ai-infrastructure-becomes-the-target-securing-gateways/</link><pubDate>Thu, 27 Aug 2026 21:01:55 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-27-when-ai-infrastructure-becomes-the-target-securing-gateways/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Microsoft Threat Intelligence documents active exploitation of exposed LiteLLM gateways leading to credential theft and persistence — no KEV or PoC signal, but if you run LiteLLM or similar AI proxies, audit internet exposure, rotate API keys, and verify no unauthorized processes are running on those hosts.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Active attack chain with detectable post-exploitation stages (credential harvesting, persistence, cryptomining) reported by Microsoft TI — pull the blog post for IOCs, then hunt for anomalous processes and outbound connections on any hosts running AI gateway software since the publication date.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> AI workloads are now an established attack surface for credential theft and resource abuse; this quarter, ensure AI infrastructure (gateways, API proxies, GPU hosts) is included in your hardening and access-review scope alongside traditional edge assets.&lt;/li>
&lt;/ul></description></item><item><title>Decentralized Confidential Computing for AI Workloads via Intel TDX</title><link>https://curasec.metacog.co.kr/insights/2026-07-27-decentralized-compute-on-untrusted-hardware-using-intel-tdx/</link><pubDate>Mon, 27 Jul 2026 15:10:27 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-27-decentralized-compute-on-untrusted-hardware-using-intel-tdx/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> Academic proposal combining Intel TDX, Intel Trust Authority, and NVIDIA Confidential Computing into a decentralized CVM platform — worth reviewing if you&amp;rsquo;re evaluating confidential compute options for protecting model weights or training data, but no production tooling or immediate action follows from this paper.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>NadMesh Botnet Targets Exposed AI Services to Steal Cloud Keys and K8s Tokens</title><link>https://curasec.metacog.co.kr/insights/2026-07-18-new-nadmesh-botnet-hunts-exposed-ai-services-for-cloud-keys/</link><pubDate>Sat, 18 Jul 2026 11:51:11 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-18-new-nadmesh-botnet-hunts-exposed-ai-services-for-cloud-keys/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> Actively scanning for internet-exposed instances of ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio to harvest AWS keys and Kubernetes tokens — exactly the stack teams deploy fast without firewall controls. Audit now for public exposure of these service ports, restrict to internal networks, and rotate AWS/K8s credentials on any host that ran them exposed.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> The TTPs are concrete enough to build detections around: Shodan-driven scanning targeting AI service endpoints, followed by credential exfiltration. Build hunts for unusual outbound traffic or credential API calls originating from AI service hosts; the summary appears truncated so IOCs are not yet available to act on directly.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> A claimed harvest of 3,811 AWS keys illustrates the systemic risk of teams rapidly standing up AI infrastructure without security review. Raise with engineering and DevSecOps leadership to establish a deployment standard for AI tooling that includes network isolation requirements before services go live.&lt;/li>
&lt;/ul></description></item></channel></rss>