← nejvýznamnější zprávy · všechny zprávy

KEV ✓ (3 z 3) EPSS 0.84 (nejvyšší)

When AI infrastructure becomes the target: Securing gateways and control points

In this article AI workloads are becoming high-value control pointsCase study 1: LiteLLM gateway compromiseCase study 2: RAGFlow compromiseCase study 3: Kestra compromiseMitigation and protection guidanceMITRE ATT&CK techniques observedReferencesLearn more AI is creating a new layer of enterprise infrastructure. Gateways, retrieval platforms, orchestration services, and containerized runtimes now sit between users, applications, data, and models. These systems concentrate credentials, data…

Číst originál na Microsoft Security Blog →

CZ · EN/orig

LiteLLM RAGFlow Kestra US

tg: zneužíváno tg: rozbor tp: AI tp: identita

CVE v události 3

CVEhodnoceníKEVEPSS
CVE-2026-42271 8.8 3.1 · redhat-SADP 8.7 4.0 · GitHub_M KEV ✓ 0.84
CVE-2026-48710 6.5 3.1 · GitHub_M 6.5 3.1 · redhat-SADP KEV ✓ 0.36
CVE-2026-49869 10.0 3.1 · GitHub_M KEV ✓ 0.02

Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE.