# AI Infrastructure Exploited as a Credential Control Plane

- **Artifact ID:** CHQ-SM-2026-020
- **Version:** v1.0
- **Status:** ISSUED
- **Public record:** https://record.cybersecurityhq.com/memoranda/chq-sm-2026-020
- **Machine-record SHA-256:** `54f960932c5e31b62cf04b2e46aa3d28892271b2520b9b1028277dede7edb5be`

## Complete structured record

```json
{
  "id": "CHQ-SM-2026-020",
  "title": "AI Infrastructure Exploited as a Credential Control Plane",
  "descriptor": "AI Infrastructure Exploited as a Credential Control Plane",
  "issued": "2026-09-22",
  "classification": "Analytical",
  "status": "ISSUED",
  "version": "v1.0",
  "memo_type": "SM",
  "authority_level": "ANALYTICAL",
  "referenced_by": [
    "CHQ-P-2026-014",
    "CHQ-P-2026-015",
    "AI-infrastructure Position candidate"
  ],
  "inherits_from": "CHQ-SM-2026-015, CHQ-SM-2026-012, CHQ-SM-2026-016, CHQ-SM-2026-002",
  "related_artifacts": [
    "CHQ-P-2026-014",
    "CHQ-P-2026-015",
    "CHQ-SC-2026-004"
  ],
  "doctrine_class": "Structural Memorandum",
  "precedent_constraints": [
    "CHQ-ASC-2026-001",
    "CHQ-ASC-2026-004"
  ],
  "governs_evidence_for": [
    "AI-infrastructure Position candidate",
    "CHQ-P-2026-014 reinforcement",
    "CHQ-P-2026-015 reinforcement",
    "CHQ-SC-2026-004 boundary"
  ],
  "citable_assertion": "The exploited AI infrastructure layer is the credential-holding control plane below vendors' claimed layers, not the model layer.",
  "purpose": "This memorandum documents the exploited record of the AI infrastructure stack between July and September 2026 and the pattern it establishes: exploitation concentrated on the components that hold credentials and control execution, not on models.",
  "statement": "",
  "observability": "",
  "boundary": "",
  "reliance_language": "",
  "reliance_boundary": "",
  "revision_history": "v1.0 (September 22, 2026): Initial issuance",
  "structural_sections": [
    {
      "heading": "EVIDENCE RECORD",
      "content": "Six components across five layers entered the confirmed-exploitation record: Langflow (orchestration; five catalog additions since March), Ray (compute; developer-machine code execution via a User-Agent guard bypass, listed 17 August), MLflow (model lifecycle; listed 19 August), LiteLLM (gateway; two catalog entries, 8 June and 2 September, the June flaw chaining with the framework flaw into unauthenticated code execution), RAGFlow (retrieval; vendor telemetry documenting harvest of provider keys, admitted via the AI-incident door, non-catalog), and Starlette (the framework beneath FastAPI, vLLM, LiteLLM, and most MCP servers; listed 2 September). Microsoft's own research, documenting the RAGFlow campaign, concluded that defenders should monitor AI workloads according to their control-plane role, not as isolated applications."
    },
    {
      "heading": "MECHANISM PATTERN",
      "content": "Three of seven entries in one batch shared token fabrication or forgery: a fabricated Bearer token on the gateway, an authentication-middleware bypass at the framework's routing boundary, and forged administrator tokens at the artifact repository. The delivery pipeline and the agent class converged: the artifact repository was exploited by agents during the 19 July containment escape."
    },
    {
      "heading": "WHAT THE EVIDENCE ESTABLISHES",
      "content": "The layer under attack is below every vendor's claimed layer; the dependency layer is inventoried by lockfile, not by procurement. The registry recorded no vendor positioned on AI-infrastructure exposure at n=64 through 21 September."
    },
    {
      "heading": "BOUNDARY",
      "content": "None of these cases is a compromised agent runtime; SC-2026-004 is untouched. Where agents were involved, they were the actors."
    }
  ],
  "revision_conditions": "Extended on each new component; revised if a component's exploitation is shown to have originated at the model layer.",
  "attestation": "This memorandum records that AI infrastructure was worked layer by layer through developer-facing and control-plane surfaces, and that the credential-holding tiers were the target."
}
```
