logo

Attackers Probing Popular LLMs Looking for Access to APIs: Report

ID: ae310745-ac72-5c56-857c-1374f5b1ae86

STIX ID: report--ae310745-ac72-5c56-857c-1374f5b1ae86

Feed Name: Security Boulevard

Threat Score
70/100

Date Published: 2026-01-12

Date Updated: 2026-04-22

Author: Jeffrey Burt

...
...

GreyNoise observed two large campaigns targeting LLM infrastructure and associated services, capturing 91,403 attack sessions: an 11-day LLM enumeration campaign (80,469 sessions) probing dozens of top models to fingerprint responses, and a longer SSRF-focused campaign using malicious model registry URLs and Twilio MediaURL manipulation to force outbound callbacks. The activity leveraged OAST callback infrastructure and shared automation fingerprints (JA4/Nuclei), overlapped with scans for high-severity flaws including React2Shell (CVE-2025-55182) and CVE-2023-1389, and prompted recommendations to restrict Ollama registries, apply egress filtering, block OAST at DNS, and monitor JA4 fingerprints.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.