# Exploited flaws in LiteLLM, Artifactory and Switchvox turn core IT tools into entry points for hackers

*Thursday, September 3, 2026 at 6:16 AM UTC — Hamer Intelligence Services Desk*

**Published**: 2026-09-03T06:16:02.348Z (1h ago)
**Category**: cyber | **Region**: Global
**Importance**: 7/10
**Sources**: OSINT
**Permalink**: https://hamerintel.com/data/articles/16684.md
**Source**: https://hamerintel.com/summaries

---

**Deck**: Attackers are exploiting security issues in LiteLLM, Artifactory and Switchvox to deploy crypto miners, open remote access and steal API keys, prompting U.S. authorities to add seven vulnerabilities tied to these tools to their known-exploited list.

New cyberattacks against LiteLLM, Artifactory and Switchvox show how common development and communications tools can become gateways for deeper breaches if left unpatched.

Recent reports describe attackers exploiting vulnerabilities in these products to deploy cryptocurrency mining software, establish remote access and harvest sensitive data such as API keys. In some cases, attackers are able to mint administrator tokens, giving them broad control over affected systems.

LiteLLM, used to connect applications to AI and other services, is being targeted for its role in handling keys and tokens that unlock access to external platforms. Artifactory, a repository for software packages, is being abused as a launchpad for crypto miners and reverse shells that give attackers command‑line access. Switchvox, a business communications system, is also being exploited to open remote sessions inside corporate networks.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added seven exploited vulnerabilities related to these products to its Known Exploited Vulnerabilities catalog, a list that signals to federal agencies and critical infrastructure operators that the flaws are being used in real‑world attacks and must be addressed.

For organizations that rely on these tools, the risk goes beyond higher server loads from illicit mining. A compromised software repository can taint code delivered to production, while stolen API keys from AI connectors can expose internal data and services. Remote shells on communications servers can give attackers a foothold to move laterally toward more sensitive systems.

The incidents fit a broader pattern in which attackers increasingly focus on the connective components of modern IT environments—software repositories, integration layers and communications platforms—rather than only on perimeter systems.

Signals to monitor now include the speed with which patches and mitigations are deployed, whether additional AI‑adjacent tools appear in CISA’s exploited‑vulnerability catalog, and incident reports tying major breaches to these specific flaws.
