Wiz published findings on August 27 from 90 days of monitoring decoy AI infrastructure, reporting sustained attacks against services including LiteLLM, Flowise and Langflow. The observations came from its own honeypots, rather than a survey of all deployed AI systems.
The researchers describe attacks on exposed tool servers, attempts to make agents execute operating-system commands, and theft of credentials held inside running AI services. Some sessions installed cryptocurrency-mining software. Wiz says attackers adapted their tools to the configuration files and internal workings of the targeted frameworks.
The report recommends authentication, limited cloud permissions and monitoring for AI services spawning shells. Its example natural-language injection prompt was reconstructed from observed behavior; the researchers did not capture that original prompt.
