#llmjacking

[ follow ]
fromTheregister
3 hours ago

AWS intruder pulled off AI-assisted cloud break-in in 8 mins

The Sysdig Threat Research Team said they observed the break-in on November 28, and noted it stood out not only for its speed, but also for the "multiple indicators" suggesting the criminals used large language models to automate most phases of the attack, from reconnaissance and privilege escalation to lateral movement, malicious code writing, and LLMjacking - using a compromised cloud account to access cloud-hosted LLMs.
Information security
Information security
fromSecurityWeek
6 days ago

LLMs Hijacked, Monetized in 'Operation Bizarre Bazaar'

Cybercriminals systematically scan, hijack, and monetize exposed self-hosted LLM and MCP endpoints to resell access, exfiltrate data, and move laterally.
[ Load more ]