threat-intel
Attackers Hijack Exposed AI Endpoints to Power Offensive Ops
High
Summary
Researchers at Zenity discovered attackers are exploiting exposed AI endpoints, specifically Ollama and LiteLLM, to power offensive operations. Attackers leverage these AI agents – such as Strix and HexStrike AI – without needing traditional authentication, simply knowing the endpoint's location. This tactic utilizes the inference endpoints of self-hosted AI software, allowing agents to perform tasks like web reverse-engineering and penetration testing, highlighting a significant new attack vector due to the lack of default security measures in these platforms.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
