Home
Tech Grid
News Room
Interviews
Think Stack
Articles
  • Home
  • /
  • News
  • /
  • Cybersecurity
  • /
  • AI
  • /
  • Zenity Labs Reveals Attackers Weaponizing Enterprise AI Infrastructure with LiteLLM Exploits
  • AI

Zenity Labs Reveals Attackers Weaponizing Enterprise AI Infrastructure with LiteLLM Exploits


Zenity Labs Reveals Attackers Weaponizing Enterprise AI Infrastructure with LiteLLM Exploits
  • by: Business Wire
  • |
  • July 1, 2026

Zenity Labs found attackers exploiting critical LiteLLM vulnerabilities and hijacking AI infrastructure to conduct attacks against third parties and power their own operations. The findings offer visibility into how attackers are exploiting AI infrastructure, revealing tools, techniques and procedures (TTPs). The research is based on thousands of real-world attack attempts observed across a global network of AI threat intelligence sensors.

Quick Intel

  • Attackers exploiting LiteLLM vulnerabilities to hijack AI infrastructure.

  • Hundreds of exploitation attempts targeting CVE-2026-40217 recorded same day as patch.

  • Attackers deployed Strix autonomous AI pentesting tool against production websites.

  • Exposed AI infrastructure used as free compute resources for attacker operations.

  • One attacker exposed full development environment and reconnaissance scripts.

  • Sensors identified coordinated campaign targeting CVE-2026-35029 vulnerability.

Attackers Hijacking AI Infrastructure

Zenity Labs' sensors recorded multiple instances of attackers abusing exposed LLM endpoints, attempting to attack third parties and power their own operations. In one incident, a threat actor deployed Strix, an autonomous AI pentesting tool, and attempted to direct it against a production e-commerce website. In another, the research uncovered attackers using exposed AI infrastructure as free compute resources, attempting to run their own operations—the AI equivalent of cryptomining. One group routed a multi-agent enterprise workflow through the exposed infrastructure, while another inadvertently exposed their full development environment, git history, and reconnaissance scripts through OpenAI's Codex.

Fast-Moving Attackers and Vulnerability Exploitation

Another key insight into attacker behavior is how fast they move. Zenity Labs' sensors recorded hundreds of exploitation attempts targeting CVE-2026-40217, a critical remote code execution vulnerability on LiteLLM, taking place the same day the CVE was patched. LiteLLM is one of the most widely deployed AI gateways used to route traffic across large enterprise AI environments. Over the following six weeks, the sensors recorded hundreds of attack attempts ranging from reconnaissance to full sandbox escape payloads. Zenity also observed attacks targeting additional LiteLLM vulnerabilities, including a separate server-side request forgery (SSRF) vulnerability with attempted data exfiltration through a novel variant of CVE-2024-6587. The sensors also identified a highly coordinated campaign targeting CVE-2026-35029, a vulnerability in LiteLLM's admin endpoint that has since been patched.

Methodology and Leadership Perspective

The findings are based on data collected from Zenity Labs' network of AI threat intelligence sensors, which provide direct visibility into how threat actors target and abuse AI infrastructure in the wild. The research captured thousands of attack attempts across AI environments, including exploitation attempts, reconnaissance activity and AI compute theft.

Michael Bargury, co-founder and CTO of Zenity, stated: "We've laid out traps that look and behave like enterprise AI infrastructure and agents, to gain increased visibility into attacker behavior. Attackers spotted our vulnerable AI, exploited n-day vulnerabilities and tried to leverage our AI resources to conduct real-world attacks, tipping their hands and revealing their TTPs. This is just the first drop, with more findings coming soon."

About Zenity

Zenity is the first security and governance platform purpose-built for agents spanning SaaS, homegrown platforms (Cloud) and end user devices (Endpoint). Trusted by Fortune 500 enterprises, Zenity helps security teams confidently adopt AI by delivering defense in depth with full-lifecycle coverage, from agent discovery and posture management to real-time detection, inline prevention and response. With an agent-centric approach that prioritizes how agents behave, what they access and which tools they invoke, Zenity eliminates blind spots and enforces consistent policy and controls across environments so organizations can innovate with AI without compromising security.

  • AI SecurityAI InfrastructureThreat IntelligenceCyber Security
News Disclaimer
Want to reach B2B tech decision-makers through TechIntelPro? Get our Media Kit
  • Share
Enterprise Tech News