AI infrastructure is rapidly becoming a prime target for cyber attackers. Recent research highlights how hackers are exploiting AI systems using remote code execution, prompt injection and API key theft. Over a 90-day period, attackers have shifted focus to exposed AI gateways and agent-tool integrations, turning these services into entry points for deeper cloud compromise.
Wiz.io researchers set up honeypots to mimic leading AI infrastructure components, including LiteLLM, MCP servers, LangChain, Flowise, Langflow, OpenWebUI and Node-RED. Their findings reveal that attackers are highly adaptive, developing techniques specifically to exploit the unique characteristics of these AI components.
The main avenues of attack observed include:
Many of these attacks begin with simple internet scans to identify publicly exposed AI endpoints. Attackers then probe these systems for weak authentication, default credentials or insecure integrations between agents and external tools.
The research focused on several popular AI infrastructure tools used by small and medium businesses:
Honeypots recorded attackers leveraging two main patterns:
In several cases, attackers chained multiple weaknesses: after achieving initial access through a public endpoint, they issued crafted prompts that forced agents to display or transmit sensitive credentials. These credentials were then used to launch cryptomining operations or to further compromise connected cloud services.
The Wiz.io honeypots collected data over a 90-day period, demonstrating that attacker interest in AI infrastructure is not fleeting. Instead, there is a sustained campaign targeting these emerging technologies.
The attacks were not isolated incidents but reflected a broad interest in AI systems as a viable entry point for cloud and infrastructure compromise. Attackers tailored their methods according to the specific AI tool in use, showing a degree of sophistication and awareness.
The findings indicate that exposed AI infrastructure is under active exploitation. Any organisation running LiteLLM, MCP, LangChain, Flowise, Langflow, OpenWebUI or Node-RED with public-facing endpoints, especially without authentication, is at heightened risk.
Small and medium-sized businesses are particularly vulnerable, as they are more likely to deploy these tools with default settings or weak security controls. Attackers are already scanning the internet for such instances, and successful attacks can quickly escalate to wider cloud compromise or resource abuse.
AI infrastructure is increasingly integrated into core business processes, making any compromise a potential gateway for attackers to access wider cloud environments and sensitive data. The rapid emergence of prompt injection and RCE exploits highlights the need for immediate attention to deployment security.
Organisations using the affected AI tools should take the following targeted actions:
Immediate review and hardening of AI deployments is essential to reduce risk.
Originally reported by cybersecuritynews.com .
Rob is a Founding Partner at CyPro and a highly experienced CISO. Beginning his career with a successful tenure at Deloitte, Rob has since amassed a wealth of experience, notably serving as a cyber security advisor to the UK government and spearheading cloud security transformations for several global banks.
At CyPro, Rob leads the managed service business line, working extensively across multiple sectors including telecommunications, technology, higher education, travel, and retail. He is passionate equipping small and medium-sized businesses (SMBs) with robust cyber security strategies to fuel their growth.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
