Two Separate Campaigns Target Exposed LLM Services
ID: 4edfbe2a-0746-51be-96df-e5f23b3979d5
STIX ID: report--4edfbe2a-0746-51be-96df-e5f23b3979d5
Feed Name: Dark Reading
Date Published: 2026-01-12
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
GreyNoise detected two campaigns targeting exposed LLM/API endpoints that together produced 91,403 sessions between October 2025 and January 2026. The first campaign used SSRF vectors and OAST callbacks and appears to be gray-hat research, while the second—originating from two IPs—methodically enumerated 73+ model endpoints (OpenAI, Anthropic, Meta, Google, Mistral, Alibaba, xAI, etc.), generating 80,469 sessions in 11 days and correlating to actors seen exploiting hundreds of CVEs. The report lists OAST callback domains, IPs, and prominent ASNs to block and recommends mitigations such as egress filtering, rate limiting, DNS blocking of OAST, and JA4 fingerprint monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
