Hackers Launch Over 91,000 Attacks on AI Systems Using Fake Ollama Servers
ID: 68fe3290-0ddc-5f51-abfa-3d637ae509a0
STIX ID: report--68fe3290-0ddc-5f51-abfa-3d637ae509a0
Feed Name: HackRead
GreyNoise researchers observed two active campaigns targeting AI infrastructure between October 2025 and January 2026: one using Server-Side Request Forgery (SSRF) to make AI servers call attacker-controlled hosts (with a spike of 1,688 sessions over 48 hours), and a second large-scale reconnaissance campaign that generated ~80,469 sessions from two IPs probing over 73 AI endpoints (including OpenAI-compatible, Google Gemini formats, Anthropic, Meta Llama, xAI Grok, and others) to build target lists; the report lists source IPs, session counts, and recommends restricting model downloads to trusted sources and monitoring rapid, repetitive queries.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
