logo

Hackers target misconfigured proxies to access paid LLM services

ID: e60cd60d-8a9e-5df9-ac03-a127aabdc98d

STIX ID: report--e60cd60d-8a9e-5df9-ac03-a127aabdc98d

Feed Name: Bleeping Computer

Threat Score
55/100

Date Published: 2026-01-09

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Threat actors systematically scanned and probed misconfigured proxy servers and commercial LLM endpoints, generating over 80,000 sessions across 73+ models and leveraging SSRF and model-pull injection attempts; GreyNoise captured two campaigns (one likely using OAST research infrastructure) and recommended mitigations such as restricting model pulls to trusted registries, egress filtering, DNS blocking of known callback domains, and rate-limiting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.