logo

Attackers Targeting LLMs in Widespread Campaign

ID: a91c3445-750a-5507-8735-d889c5fbda46

STIX ID: report--a91c3445-750a-5507-8735-d889c5fbda46

Feed Name: The Cyber Express

Threat Score
65/100

Date Published: 2026-01-12

Date Updated: 2026-04-23

Author: Paul Shread

...
...

Security researchers observed a large-scale reconnaissance campaign that probed over 73 LLM endpoints across major model families (OpenAI, Anthropic, Meta, Google, Mistral, Alibaba, xAI, etc.) to identify misconfigured proxies that could leak commercial API access, generating ~80,469 sessions from two primary IPs; a separate set of activity targeted SSRF vulnerabilities and webhook integrations. The report lists IOCs (IP addresses, ASNs, JA4 signature), assesses likely attacker intent to build exploitation target lists, and recommends hardening model pulls, egress filtering, rate-limiting suspicious ASNs, and detecting enumeration patterns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.