logo

Hackers Launch Over 91,000 Attacks on AI Systems Using Fake Ollama Servers

ID: 68fe3290-0ddc-5f51-abfa-3d637ae509a0

STIX ID: report--68fe3290-0ddc-5f51-abfa-3d637ae509a0

Feed Name: HackRead

Threat Score
60/100

Date Published: 2026-01-14

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

GreyNoise researchers observed two active campaigns targeting AI infrastructure between October 2025 and January 2026: one using Server-Side Request Forgery (SSRF) to make AI servers call attacker-controlled hosts (with a spike of 1,688 sessions over 48 hours), and a second large-scale reconnaissance campaign that generated ~80,469 sessions from two IPs probing over 73 AI endpoints (including OpenAI-compatible, Google Gemini formats, Anthropic, Meta Llama, xAI Grok, and others) to build target lists; the report lists source IPs, session counts, and recommends restricting model downloads to trusted sources and monitoring rapid, repetitive queries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.