Published: · Region: Global · Category: cyber

Attackers Exploit LiteLLM, Artifactory and Switchvox Flaws as CISA Adds Seven Bugs to High-Risk List

Threat actors are abusing vulnerabilities in LiteLLM, Artifactory and Switchvox to deploy crypto miners, open remote access, mint admin tokens and steal API keys. U.S. cyber authorities have added seven exploited flaws to their Known Exploited Vulnerabilities catalog, signaling that organizations using these tools face an active infrastructure risk.

A new wave of software flaws has moved from technical advisories to real-world attacks, as intruders target key tools that support software development, communications and connections to artificial intelligence services.

Recent reporting describes attackers exploiting vulnerabilities in LiteLLM, Artifactory and Switchvox. By chaining these weaknesses together, they have deployed cryptocurrency miners and reverse shells, generated unauthorized administrator tokens and harvested API keys.

In response, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added seven actively exploited vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. Federal agencies are required to remediate items on this list within set deadlines, and inclusion in the catalog is one of the clearest signs that a flaw is being used in the wild.

LiteLLM serves as a gateway to connect applications with large language models, handling API calls and credentials. Artifactory manages software components and packages in development pipelines. Switchvox provides business communications and VoIP services. Because these systems sit deep inside many networks, a breach can have wide effects.

An attacker who can mint administrator tokens or open a reverse shell can gain a foothold inside an organization. From that position, they can do more than run crypto miners: the same access can be used to move to other systems, copy code or data, or prepare more disruptive operations.

For organizations that rely on these products, the immediate concern is the theft of API keys and other credentials. These can act as master keys to critical services, allowing intruders to impersonate legitimate systems or manipulate information.

The pattern fits a broader shift in which attackers focus on the underlying tools that control software, credentials and communications rather than only attacking public-facing websites.

Key indicators to watch now include vendor patches and hardening guidance, any breach disclosures linked to these flaws, and further updates from CISA and other national agencies on how widely the vulnerabilities are being exploited.

Sources