AINewsnow

Your self-hosted AI stack is being turned into a crypto miner

This story is from 2026-09-08. It is preserved in the archive; the latest stories are on the live feed.

Microsoft has been investigating live intrusions against exactly the stack a lot of us self-host: an LLM gateway (LiteLLM), a RAG platform (RAGFlow), and a workflow runner (Kestra). The findings are not subtle — attackers read container env vars, planted a hook that steals every API key an admin sa…

Read the full story at DEV Community — AI ↗

Timeline · 1 report

  1. 2026-09-08 02:20 · DEV Community — AI
    Your self-hosted AI stack is being turned into a crypto miner

More stories

  1. Microsoft exec called AI scraping the “largest theft of labor in human history” — Ars Technica AI
  2. OpenAI staff knew the ‘existential threat’ AI posed to publishers, New York Times claims — Financial Times AI
  3. Implementing defense-in-depth authorization for MCP tools on Amazon Quick — AWS Machine Learning Blog
  4. Migrating the GitHub Copilot runtime to Rust, using Copilot — GitHub Blog
  5. OpenAI's latest AI revelation is a 'serious situation,' Microsoft's Suleyman tells CNBC — CNBC Technology
  6. OpenAI and Microsoft knew they were starting a ‘doom loop’ for the web — The Verge AI
  7. A zero-click RCE flaw in AI coding agents could have exposed enterprise systems — InfoWorld AI
  8. Microsoft AI CEO says AI threats are real, and Anthropic is making it worse — The Verge AI

Get the daily brief of stories like this at 6:30 every morning →