<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Credential-Harvesting on CuraSec</title><link>https://curasec.metacog.co.kr/tags/credential-harvesting/</link><description>Recent content in Credential-Harvesting on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Thu, 27 Aug 2026 21:01:55 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/credential-harvesting/index.xml" rel="self" type="application/rss+xml"/><item><title>Microsoft TI: LiteLLM gateways actively exploited for cred theft and cryptomining</title><link>https://curasec.metacog.co.kr/insights/2026-08-27-when-ai-infrastructure-becomes-the-target-securing-gateways/</link><pubDate>Thu, 27 Aug 2026 21:01:55 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-27-when-ai-infrastructure-becomes-the-target-securing-gateways/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Microsoft Threat Intelligence documents active exploitation of exposed LiteLLM gateways leading to credential theft and persistence — no KEV or PoC signal, but if you run LiteLLM or similar AI proxies, audit internet exposure, rotate API keys, and verify no unauthorized processes are running on those hosts.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Active attack chain with detectable post-exploitation stages (credential harvesting, persistence, cryptomining) reported by Microsoft TI — pull the blog post for IOCs, then hunt for anomalous processes and outbound connections on any hosts running AI gateway software since the publication date.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> AI workloads are now an established attack surface for credential theft and resource abuse; this quarter, ensure AI infrastructure (gateways, API proxies, GPU hosts) is included in your hardening and access-review scope alongside traditional edge assets.&lt;/li>
&lt;/ul></description></item></channel></rss>