THREAT OPS › Threat News › When AI infrastructure becomes the target: Securing gateways and control points
When AI infrastructure becomes the target: Securing gateways and control points
<aside class="table-of-contents-block accordion wp-block-bloginabox-theme-table-of-contents" id="accordion-3ce1ad60-18ec-436f-83e6-614f329dd287"> <button class="btn btn-collapse" type="button"> <span class="table-of-contents-block__label">In this article</span> <span class="table-of-contents-block__current"></span>
<svg class="table-of-contents-block__arrow" fill="none" height="11" viewBox
MITRE ATT&CK techniques
- Linux and Mac PermissionsT1222.002
- Match Legitimate Resource Name or LocationT1036.005
- CronT1053.003
- VulnerabilitiesT1588.006
- Application Layer ProtocolT1071
- Data from Local SystemT1005
- Exploit Public-Facing ApplicationT1190
- MasqueradingT1036
- Unsecured CredentialsT1552
- File and Directory Permissions ModificationT1222
- SSH Authorized KeysT1098.004
- Command and Scripting InterpreterT1059
- Credentials In FilesT1552.001
- Process DiscoveryT1057
- Social MediaT1593.001
- CredentialsT1589.001
- Non-Application Layer ProtocolT1095
- Resource HijackingT1496
- System ServicesT1569
- Template InjectionT1221
- Web ProtocolsT1071.001
- Systemd ServiceT1543.002
- Software DiscoveryT1518
- Hidden Files and DirectoriesT1564.001
- Generative AIAML.T0016.002
- Data from Local SystemAML.T0037
- Exploit Public-Facing ApplicationAML.T0049
- Command and Scripting InterpreterAML.T0050
- Unsecured CredentialsAML.T0055
- Reverse ShellAML.T0072
- MasqueradingAML.T0074
- Process DiscoveryAML.T0089
Indicators of compromise
- f64b88e9318bdf23f2dd119a0ce1dd1bdb3c8cd2e0e1e23ba3ef2e19072b79ccsha256
- 49fdcf32bfe837899a84e8938f0d07ae96ddd218a280a09eb60df8d64597bd8fsha256
- 3af9f25a4d45bb4f1ec5627cdbc6703cf3b4be75a892162d299d80ddfb266f42sha256
- 3d24ac736635e0fa0c5c459c9e18ca09d1ec9a1751a4503130934395609bd7e0sha256
- CVE-2026-42271cve
- CVE-2026-48710cve
- CVE-2026-49869cve
- CVE-2026-45312cve
- CVE-2026-28797cve
- CVE-2026-24770cve
- CVE-2025-68700cve
- CVE-2025-69286cve
- https://www.cve.org/CVERecord?id=CVE-2026-42271url
- https://www.cve.org/CVERecord?id=CVE-2026-48710url
- https://docs.litellm.ai/docs/proxy/virtual_keysurl
- https://horizon3.ai/attack-research/vulnerabilities/cve-2026-42271-chained-with-cve-2026-48710/url
- https://www.cve.org/CVERecord?id=CVE-2026-45312url
- https://www.cve.org/CVERecord?id=CVE-2026-28797url
- https://www.cve.org/CVERecord?id=CVE-2025-68700url
- https://www.cve.org/CVERecord?id=CVE-2025-69286url
- https://www.cve.org/CVERecord?id=CVE-2026-49869url
- https://microsoft.github.io/zerotrustassessment/url
- 45.150.109.151ipv4
- 135.125.10.56ipv4
- 172.232.38.92ipv4
- 47.86.197.116ipv4
- 194.213.18.133ipv4
- sslip.iodomain
- yosemite.jpdomain
- gobygo.netdomain
- oast.medomain
- auto.c3pool.orgdomain
- 45.150.109.151.sslip.iodomain