{"id":9756,"date":"2026-01-09T10:03:40","date_gmt":"2026-01-09T10:03:40","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/01\/09\/hackers-actively-exploiting-ai-deployments-91000-attack-sessions-observed\/"},"modified":"2026-01-09T10:03:40","modified_gmt":"2026-01-09T10:03:40","slug":"hackers-actively-exploiting-ai-deployments-91000-attack-sessions-observed","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/01\/09\/hackers-actively-exploiting-ai-deployments-91000-attack-sessions-observed\/","title":{"rendered":"Hackers Actively Exploiting AI Deployments \u2013 91,000+ Attack Sessions Observed"},"content":{"rendered":"<p>    Hackers Actively Exploiting AI Deployments \u2013 91,000+ Attack Sessions Observed<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Security researchers have identified over 91,000 attack sessions targeting <a href=\"https:\/\/cybersecuritynews.com\/cyber-attacks-against-ai-infrastructure\/\" target=\"_blank\" rel=\"noreferrer noopener\">AI infrastructure<\/a> between October 2025 and January 2026, exposing systematic campaigns against large language model deployments.<\/p>\n<p>GreyNoise\u2019s Ollama honeypot infrastructure captured 91,403 attack sessions during this period, revealing two distinct threat campaigns. The findings corroborate and extend previous research from Defused on AI system targeting.<\/p>\n<p>The first campaign exploited <a href=\"https:\/\/cybersecuritynews.com\/server-side-phishing-attacks-employees-member-portals\/\" target=\"_blank\" rel=\"noreferrer noopener\">server-side<\/a> request forgery vulnerabilities to force servers into making outbound connections to attacker-controlled infrastructure.<\/p>\n<p>Attackers targeted Ollama\u2019s model pull functionality by injecting <a href=\"https:\/\/cybersecuritynews.com\/hackers-deliver-xworm-via-malicious-registry-files\/\" target=\"_blank\" rel=\"noreferrer noopener\">malicious registry<\/a> URLs and manipulating Twilio SMS webhook MediaUrl parameters.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgLUQ1fnKf9ZHt5vn1jOTWlztU7h_rKElbmScTlPmnfNjwpfSNgn0fgtX5hVWN3-JGjIkNfiw9vGAfDs4YbMiQBa0Ou7LRPvSmqfonvjdulQhyphenhyphenLfWI0u6f9YoXayg6J1-2voCD9othOy5IiugjFR4zmwxZbuIio5x3rxNnTWXhN-XOqUiWWc9Q_LuW2sIc\/s1600\/Screenshot%25202026-01-09%2520105611%2520%25281%2529.webp?ssl=1\" alt=\"Ollama SSRF &amp; Enumeration\"><figcaption class=\"wp-element-caption\">SSRF Enumeration (Source: Greynoise)<\/figcaption><\/figure>\n<p>The campaign ran from October 2025 through January 2026, with a dramatic spike over Christmas, 1,688 sessions in just 48 hours.<\/p>\n<p>Attackers used ProjectDiscovery\u2019s <a href=\"https:\/\/cybersecuritynews.com\/mystery-oast-with-exploit-for-200-cves\/\" target=\"_blank\" rel=\"noreferrer noopener\">OAST<\/a> infrastructure to confirm successful exploitation via callback validation.<\/p>\n<p>Fingerprinting revealed a single JA4H signature appearing in 99% of attacks, indicating shared automation tooling likely based on Nuclei.<\/p>\n<p>While 62 source IPs spread across 27 countries were observed, consistent fingerprints suggest VPS-based infrastructure rather than a botnet.<\/p>\n<p>GreyNoise <a href=\"https:\/\/www.greynoise.io\/blog\/threat-actors-actively-targeting-llms\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">assesses<\/a> this as probable grey-hat operations by bug bounty hunters, though the scale and timing raise ethical concerns.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-enumeration-campaign-building-target-lists\"><strong>Enumeration Campaign: Building Target Lists<\/strong><\/h2>\n<p>Starting December 28, 2025, two IPs launched methodical probes of 73+ <a href=\"https:\/\/cybersecuritynews.com\/vigil-open-source-security-scanner\/\" target=\"_blank\" rel=\"noreferrer noopener\">LLM model<\/a> endpoints, generating 80,469 sessions in eleven days.<\/p>\n<p>This systematic reconnaissance sought misconfigured proxy servers that might expose access to commercial APIs.<\/p>\n<p>The attacks tested OpenAI-compatible and <a href=\"https:\/\/cybersecuritynews.com\/google-gemini-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">Google Gemini<\/a> formats across every major model family: OpenAI GPT-4o, Anthropic Claude, Meta Llama 3.x, DeepSeek-R1, Google Gemini, Mistral, Alibaba Qwen, and xAI Grok.<\/p>\n<p>Test queries remained deliberately innocuous, with \u201chi\u201d appearing 32,716 times and \u201cHow many states are there in the United States?\u201d appearing 27,778 times, likely aiming to fingerprint models without triggering security alerts.<\/p>\n<p>The infrastructure points to professional threat actors: 45.88.186.70\u00a0(AS210558, 1337 Services GmbH): 49,955 sessions 204.76.203.125\u00a0(AS51396, Pfcloud UG): 30,514 sessions<\/p>\n<p>Both IPs have extensive histories of CVE exploitation, with over 4 million combined sensor hits across more than 200 vulnerabilities, including <a href=\"https:\/\/cybersecuritynews.com\/react2shell-cve-2025-55182-attacks-rsc-enabled-services\/\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2025-55182<\/a> and CVE-2023-1389.<\/p>\n<p>Block these network indicators:<\/p>\n<figure class=\"wp-block-table is-style-stripes\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th>JA4H<\/th>\n<th>Domains<\/th>\n<th>IPs<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><code>po11nn060000...<\/code><\/td>\n<td><code>*.oast.live, *.oast.me, *.oast.online, *.oast.pro, *.oast.fun, *.oast.site, *.oast.today<\/code><\/td>\n<td><code>45.88.186.70, 204.76.203.125, 134.122.136.119, 134.122.136.96, 112.134.208.214, 146.70.124.188, 146.70.124.165<\/code><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p>Allow Ollama to make outbound connections only to approved addresses. Block all other outgoing traffic so attackers can\u2019t use it for <a href=\"https:\/\/cybersecuritynews.com\/sliver-c2-server-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">SSRF callbacks.<\/a><\/p>\n<p>Eighty thousand enumeration requests represent a significant investment. <a href=\"https:\/\/cybersecuritynews.com\/threat-actors-leversges-google-cloud-services\/\" target=\"_blank\" rel=\"noreferrer noopener\">Threat actors<\/a> don\u2019t map infrastructure at this scale without plans to exploit it.<\/p>\n<p>If you\u2019re running exposed LLM endpoints, you\u2019re likely already on someone\u2019s target list.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/hackers-exploiting-ai-deployments\/\">Hackers Actively Exploiting AI Deployments \u2013 91,000+ Attack Sessions Observed<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/hackers-exploiting-ai-deployments\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hackers Actively Exploiting AI Deployments \u2013 91,000+ Attack Sessions Observed Security researchers have identified over 91,000 attack sessions targeting AI infrastructure between October 2025 and January 2026, exposing systematic campaigns against large language model deployments. GreyNoise\u2019s Ollama honeypot infrastructure captured 91,403 attack sessions during this period, revealing two distinct threat campaigns. The findings corroborate and [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[167,129,63],"tags":[130],"class_list":["post-9756","post","type-post","status-publish","format-standard","hentry","category-ai","category-cyber-security","category-cyber-security-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9756"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=9756"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9756\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=9756"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=9756"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=9756"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}