Hundreds of LLM Servers Expose Corporate, Health & Other Online Data
ID: 863e1dfe-0eb2-5b09-8519-bf58e3660c87
STIX ID: report--863e1dfe-0eb2-5b09-8519-bf58e3660c87
Feed Name: Dark Reading
A researcher scanned the web and found hundreds of Flowise LLM builder instances and roughly 30 vector database servers improperly secured; using a known authentication-bypass vulnerability (CVE-2024-31621) the researcher accessed dozens of Flowise servers and discovered exposed GitHub tokens, OpenAI API keys, plaintext passwords, and application data, while open vector DBs contained PII, corporate documents, medical data, and other sensitive content—risks include credential theft, data exfiltration, and poisoning or tampering of AI data stores.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
