175,000 Exposed Ollama Hosts Enable Code Execution and External System Access
ID: 5a0e641a-c2da-50fe-93f6-f168db1c9b66
STIX ID: report--5a0e641a-c2da-50fe-93f6-f168db1c9b66
Feed Name: cybersecurityNews.com
Threat Score
Researchers discovered roughly 175,000 publicly reachable Ollama servers caused by simple misconfiguration (binding to 0.0.0.0), creating widespread risk of remote code execution and unauthorized access; nearly half of hosts support tool-calling (38% with text completion and tool execution), many have vision and reasoning capabilities, and a monoculture of identical model formats amplifies the potential blast radius across 130 countries and 4,032 ASNs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
