All posts
Topic
Credential Theft
4 articles on credential theft.
When Your LLM Router Turns On You: Tool-Call Injection and Credential Theft
A defensive brief on a fast-rising risk class: malicious or compromised LLM routers and MCP gateways that inject unintended tool calls, steal credentials in transit, and pivot across hosts. What the attack looks like, why it scales, and the controls that actually contain it.
September 11, 2026
Critical Langflow Flaw (CVE-2026-0768) Now Exploited en Masse to Steal OpenAI & AWS Keys
Attackers are mass-exploiting CVE-2026-0768, a CVSS 9.8 unauthenticated RCE in the Langflow AI app builder, to run code as root and harvest OpenAI API keys and cloud secrets. What the flaw is, why AI gateways are the target, and what to do today.
September 4, 2026
CISA Flags LiteLLM CVE-2026-59822: Attackers Forge Authenticated MCP Sessions With No Credentials
CISA added LiteLLM CVE-2026-59822 (CVSS 8.8) to its Known Exploited Vulnerabilities catalog on Sep 3, 2026 โ an unauthenticated attacker can establish an authenticated MCP session against the popular AI gateway. Why the gateway is the prize, and how to respond.
September 3, 2026
Attackers Are Hunting Your AI Gateway: Inside the LiteLLM / RAGFlow / Kestra Campaign
Microsoft detailed a coordinated campaign (Aug 2026) hitting exposed AI infrastructure โ LiteLLM, RAGFlow, Kestra โ to steal every model-provider API key and then mine crypto on the box. The CVEs, the credential-harvesting playbook, and how to lock your AI control points down.
August 26, 2026