Wiz Research pointed a scanner at internet-facing LiteLLM gateways and found that nearly one in ten still accepted sk-1234, the example admin key printed in the project’s own setup guide. That is a cybersecurity finding you can explain to a director in one sentence, and it still sounds like a joke until you remember the key is the administrator credential for the proxy sitting between your apps and the model providers you pay.

Anyone who holds it can read prompts, lift provider tokens, and steer billed traffic. The same week, the EU Cyber Resilience Act starts forcing a 24-hour government notice when you discover a serious product security incident. Friday is not a blog post. It is a clock.

The setup guide is a credential dump now

LiteLLM is an open-source AI gateway. You drop it in front of the model APIs your developers already call so the company gets one route, one spend control, and one place to attach policy. That pattern is spreading because every team wants a chat feature and nobody wants seven vendor SDKs in production. The failure is simpler than the architecture. The documented sample became a live secret.

Wiz’s February scan is the detail that should follow you into standup. These hosts were on the public internet. The password was in the tutorial. A brute-force campaign is wasted work when the README still works. An unauthenticated stranger used the login the docs told them to try, and the gateway said yes.

LiteLLM AI gateway interface associated with exposed example admin keys
LiteLLM is a choke point for prompts and provider keys. An example admin credential on that box is a privileged identity wearing a developer-tool costume.

If your copy lives only on an internal VLAN, keep reading. Internal is where the provider keys live, where prompts include customer data, and where tool-calling gets wired to tickets and source control. An admin key on that box is a crown-jewel identity. It just happens to look like a convenience feature.

Example secrets keep clearing threat-protection controls because the login is valid. Threat detection that watches for sprays and lockouts will stay quiet. Failed-auth dashboards will look healthy. The attacker logs in once and looks like the person who stood up the proof of concept in January.

Ownership is the other leak. A lot of cyber security programs still treat the IdP, the VPN, and the domain controllers as the privileged set, while platform or data-science groups stand up gateways that never appear in the access review. Docs are sticky. So are Helm values copied from a blog post at 11 p.m. If you have more than one of these, and you do, assume the sample survived.

Friday’s 24-hour clock starts whether you’re ready

Starting Friday, businesses operating in the EU get a hard window: 24 hours to notify the government after discovering a serious product security incident. If you ship software, firmware, or a connected device into that market, you are on the hook even when the engineering team and the SOC sit somewhere else.

Padlock symbolizing EU product security and cyber resilience regulation
The Cyber Resilience Act turns a product bug you already knew about into a timed notice problem. Your IR runbook has to start that clock when you actually learn, not when the ticket looks tidy.

Hold that rule next to the rest of the week. A tutorial admin key on a production gateway is a product defect the moment you learn it was reachable. Fortinet’s unauthenticated code execution hole, CVE-2025-25249, was patched in January 2026 and is now being used to drop the PivotC2 RAT. That is a vendor product incident and your containment problem in the same hour. ShieldCrash, a Microsoft Defender zero-day, yields full SYSTEM on Windows machines that already installed the September 2026 patches. The process you installed to be the adult on the box is the exploit path.

Lawyers will argue what counts as a “product” and what counts as “serious.” Let them. You still need a named owner who can start the clock, a path to counsel that does not wait for the Monday governance meeting, and notes that show when you actually learned. Incident response that treats notice as a comms deliverable after eradication will miss a regulatory deadline while the channel is still arguing over severity.

US-only shops still inherit the tempo from EU customers, insurers, and questionnaires. If your runbook still says you draft the statement in three business days, you are writing fiction.

Pull the demo keys and the management planes

You do not need a new category of platform for this. You need an asset list that includes AI proxies, then a pass that assumes someone copied the docs into prod.

Do these in real environments this week, without waiting for a task force name:

  • Inventory every AI gateway, LLM proxy, model router, and admin UI the same way you inventory VPNs and jump hosts, including shadow containers and “temporary” cloud instances. If it is missing from the list, it is unowned, and unowned is how sk-1234 lives for months.
  • Rotate gateway admin keys and every downstream provider key those gateways can see. Treat documented examples, empty master keys, and README secrets as already stolen. Issue replacements from a vault. Do not paste the new secret into chat so the old incident can have a friend.
  • Move management listeners off the internet. Put SSO in front of the console. Disable static local admin keys where the product allows it. Where it does not, restrict source IPs and open a vendor ticket; that gap is a CRA-shaped problem if you sell the stack into Europe.
  • Prove Fortinet and other edge gear are on a build that includes the January 2026 fix for CVE-2025-25249, then hunt for PivotC2-style callbacks from those devices. Patch proof is the running version plus a config hash, not a calendar invite that said “patch week.”
  • On Windows, treat ShieldCrash as SYSTEM until your vendor says the exploit is dead. Watch Defender crash and telemetry anomalies, starve local staging paths, and handle an endpoint-agent failure as a privileged-host event.

That bundle is security hardening you can finish without a new budget line. Defense in depth, in practical terms, means a docs password cannot reach the gateway, the appliance admin plane is not a public service, and a Defender SYSTEM bug does not equal forest-wide control because the workstation was never that trusted.

Keep the loop going after Friday. Put example-secret checks into CI and into external attack-surface scans. Add “default credential on the AI proxy” to the tabletop. Rehearse the 24-hour product notice with legal the way you already rehearse ransomware statements. If you sell into the EU, map which SKUs are CRA products and who gets paged at 2 a.m. when a researcher posts a screenshot.

Your cybersecurity program already owns these products

Plenty of teams still file “our misconfig” and “their zero-day” in different folders. Attackers file both under access. PivotC2 crews are walking through a Fortinet bug that had a patch before summer. ShieldCrash goes through Defender on hosts that did the patching you were proud of in September. The sample LiteLLM key did not even need a vulnerability.

Fortinet security appliance associated with exploited code execution vulnerability CVE-2025-25249
CVE-2025-25249 had a January patch. PivotC2 operators are using it anyway. A fix on the calendar is not the same thing as a fix on the device answering the internet.

Your firewall still earns its keep on the paths you actually close. It will not invent a rotation you skipped, and it will not turn an exploited management plane into a non-event. Product risk is operational risk, and in the EU it now arrives with a government timer.

If you only do one thing before Friday’s coffee, export the listen addresses of every AI gateway and every appliance admin portal, kill the sample secrets, and write the product-notice paragraph into the IR plan. The tutorial password is still production in too many places. You can stop being one of them this afternoon.

Sources

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.

Stay up to date with the latest news, releases and more.

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.