Wednesday , August 26 2026
175,000

Researchers Identify 175,000 Exposed Ollama AI Servers in 130 Countries

A joint investigation by SentinelOne SentinelLABS and Censys found that open-source AI deployment has led to a large “unmanaged, publicly accessible AI compute infrastructure” with 175,000 unique Ollama hosts in 130 countries.

These systems operate outside the usual safety and monitoring measures set by platform providers. According to the company, over 30% of these vulnerabilities are in China. The countries with the most infrastructure include the U.S., Germany, France, South Korea, India, Russia, Singapore, Brazil, and the U.K.

Crack 85 Accounts and Steal 2,500+ Records
8-Agent AI Framework Used to Compromise Gov’t Entities in Asia

A cyberattack using open-source AI tools almost ran on its own. It affected government systems in Asia, compromised into 85...
Read More
Crack 85 Accounts and Steal 2,500+ Records  8-Agent AI Framework Used to Compromise Gov’t Entities in Asia

270+ Zimbra servers compromised in continuous attacks

Threat actors have already compromised more than 270 Zimbra instances in attacks that let them run code remotely. These attacks...
Read More
270+ Zimbra servers compromised in continuous attacks

Singapore Approves 200MW Data-Centre Expansion Under Second Call

Singapore has picked four data-centre plans for a total of 200MW of power in its second Data Centre Call for...
Read More
Singapore Approves 200MW Data-Centre Expansion Under Second Call

Chameleon SEO Poisoning
Hackers poison Bing and Google search results to deliver phishing banking pages

Bank customers looking for a login page can now fall into a trap before getting a strange email or text....
Read More
Chameleon SEO Poisoning  Hackers poison Bing and Google search results to deliver phishing banking pages

Mysterious AI model “Ox Alpha” with free 100 trillion tokens a day for coders

A mysterious AI model dubbed "Ox Alpha" has surfaced online and created noise within the developer community after releasing on...
Read More
Mysterious AI model “Ox Alpha” with free 100 trillion tokens a day for coders

After BDJobs, Directorate of Secondary and Higher Education 390k data surfaced online

A group of hackers named “Madarax” claims they have stolen and are offering to sell the personal information of about...
Read More
After BDJobs, Directorate of Secondary and Higher Education 390k data surfaced online

Researchers show new technique to bypass AI safety guardrails in Grok and Gemini

A new hacking technique has been demonstrated to steal data from Elon Musk's Grok AI. It uses a simple trick...
Read More
Researchers show new technique to bypass AI safety guardrails in Grok and Gemini

About thousands of leaked AWS keys Held Full Admin Rights

More than 9,300 AWS access keys that were made public from August 2022 to August 2026 are still active, says...
Read More
About thousands of leaked AWS keys Held Full Admin Rights

US Bank investigates LockBit’s Data Breach Claims

US Bank is looking into LockBit's claims about a breach and stolen data. The ransomware group says they will share...
Read More
US Bank investigates LockBit’s Data Breach Claims

Five new malware families actively targeting Asian Gov.t infra

Central Asian government agencies have been attacked in a cyber spy operation that used a small but different range of...
Read More
Five new malware families actively targeting Asian Gov.t infra

“Nearly half of observed hosts are configured with tool-calling capabilities that enable them to execute code, access APIs, and interact with external systems, demonstrating the increasing implementation of LLMs into larger system processes,” researchers Gabriel Bernadett-Shapiro and Silas Cutler added.

Ollama is an open-source tool for easily downloading, running, and managing large language models (LLMs) on Windows, macOS, and Linux.

The service defaults to the localhost address 127.0.0[.]1:11434, but you can easily make it public by changing the binding to 0.0.0[.]0 or a public interface.

Ollama and Moltbot (previously Clawdbot) are both hosted locally, creating new security issues since they operate beyond enterprise defenses. Researchers emphasize the need for new methods to differentiate managed and unmanaged AI computing.

Over 48% of the observed hosts offer tool-calling features through their API endpoints, which return metadata about their functionalities. Tool calling lets LLMs connect with external systems, APIs, and databases, enhancing their abilities and providing real-time data.

“Tool-calling capabilities fundamentally alter the threat model. A text-generation endpoint can produce harmful content, but a tool-enabled endpoint can execute privileged operations,” the researchers noted. “When combined with insufficient authentication and network exposure, this creates what we assess to be the highest-severity risk in the ecosystem.”

The analysis has also found hosts supporting various functions, like reasoning and vision, with 201 hosts running unrestricted prompt templates that lack safety measures.

These systems are vulnerable to LLMjacking, where attackers misuse a victim’s LLM resources, forcing them to pay for the damage. This can involve creating spam emails, spreading misinformation, mining cryptocurrency, or selling access to criminals.

A recent Pillar Security report reveals that threat actors are actively exploiting exposed LLM service endpoints in a campaign called Operation Bizarre Bazaar to monetize AI infrastructure.

The results indicate a criminal operation with three parts: searching the internet for unsecured Ollama instances, vLLM servers, and OpenAI-compatible APIs without authentication, testing the response quality, and selling access at lower prices through advertising on silver[.]inc as a Unified LLM API Gateway.

“This end-to-end operation – from reconnaissance to commercial resale – represents the first documented LLMjacking marketplace with complete attribution,” researchers Eilon Cohen and Ariel Fogel said. The operation has been traced to a threat actor named Hecker (aka Sakuya and LiveGamer101).

The decentralized Ollama ecosystem, found in both cloud and residential settings, leads to governance issues and allows for malicious traffic injection through victim networks.

“The residential nature of much of the infrastructure complicates traditional governance and requires new approaches that distinguish between managed cloud deployments and distributed edge infrastructure,” the companies said. “For defenders, the key takeaway is that LLMs are increasingly deployed to the edge to translate instructions into actions. As such, they must be treated with the same authentication, monitoring, and network controls as other externally accessible infrastructure.”

Check Also

Zoom Flaw

AI Finds Nation-State-Level Zoom Flaw in Under 24 Hours, Zero-Click Attack Exposed

A serious security flaw in Zoom might let a hacker take control of someone else’s …