Request routing needs host monitoring
Microsoft reports intrusions across three infrastructure systems. Request-routing infrastructure needs host and network monitoring.

Request-routing infrastructure needs host and network monitoring. Application records cover requests, but they cannot account for every shell command, secret read, file change, container action, or outbound connection on the host.
A gateway is software that routes requests. Its application logs remain necessary. Muniment’s position is that operators should connect those logs to host and network events around the same request-routing process.
Microsoft reports intrusions against a model gateway, a RAGFlow deployment, and a Kestra workflow environment. Microsoft observed attackers seeking credentials, persistent access, and computing resources for mining. Persistent access means access that survives a restart.
Microsoft, RAGFlow, and Kestra are neither Muniment customers nor endorsers.
Three systems exposed three execution paths
Microsoft describes different entry paths and activity in each workload:
- For the model gateway, Microsoft observed secret collection, database access, miner deployment, and changes intended to preserve access. Microsoft assesses with high confidence that initial access likely came through the exposed gateway. The word “likely” matters because Microsoft presents an assessment, not a confirmed entry path.
- For RAGFlow, Microsoft observed possible server-side request probing before code execution and application-file changes. Microsoft has low confidence about which specific vulnerability, if any, enabled that execution. Microsoft calls the public vulnerability paths plausible context and does not confirm one as the cause.
- For Kestra, Microsoft observed workflow-started shell activity, container runtime access, container discovery, miner deployment, and later data collection. Microsoft assesses with high confidence that initial access likely involved the exposed Kestra service. Here too, Microsoft states an assessment rather than a confirmed entry path.
Persistence needs a precise definition in the RAGFlow record. Microsoft observed a startup-path modification that could survive service restarts if the changed files remained. Microsoft also notes that the durability of access written inside the container depends on container privileges, file persistence, and boundary configuration.
Monitor from the application parent process
Microsoft identified the model gateway process as the origin of later shell and Python execution. In RAGFlow, Microsoft placed the observed execution inside the application container and runtime lineage. In Kestra, Microsoft traced shell activity to the workflow worker.
Operators can connect a host alert to the request-routing event that preceded it. Keep the parent process, request identity, service account, container identity, file events, and network events in one timeline. This is Muniment’s operating conclusion from Microsoft’s report.
Microsoft advises defenders to correlate unexpected application-started shells or interpreters with secret access, application-file changes, container runtime access, outbound callbacks, and resource hijacking. Microsoft also recommends restricting administrative access, limiting outbound traffic, and watching changes to scheduled jobs and authorized access files.
A gateway record identifies who sent a request and where it went. Host and network records can show what the routing process did outside that request. Operators need both records when the software that routes model requests also holds keys, reaches data, or starts work.