Executive Summary
Between March and May 2026, Zenity researchers identified three distinct campaigns where threat actors exploited exposed AI inference endpoints, such as those of Ollama and LiteLLM, to conduct offensive operations. These attacks did not require full system compromises; attackers merely needed knowledge of the exposed endpoints to leverage them for activities like autonomous penetration testing and web reverse-engineering. The incidents underscore the critical need for securing AI infrastructure against unauthorized access.
This trend highlights a growing tactic among cyber adversaries: exploiting misconfigured or exposed AI endpoints to amplify their offensive capabilities. As organizations increasingly integrate AI into their operations, ensuring the security of these systems becomes paramount to prevent their misuse in cyberattacks.
Why This Matters Now
The exploitation of exposed AI endpoints represents an emerging threat vector, emphasizing the urgency for organizations to secure their AI infrastructures to prevent unauthorized access and potential misuse in cyber operations.
Attack Path Analysis
Attackers exploited exposed AI inference endpoints lacking authentication to gain unauthorized access. They then configured AI agents to operate with elevated privileges, enabling further malicious activities. Utilizing the compromised AI infrastructure, attackers moved laterally to other systems within the network. They established command and control channels through the AI agents to orchestrate their operations. Sensitive data was exfiltrated via the compromised AI endpoints. The attack culminated in the disruption of AI services and potential data manipulation.
Kill Chain Progression
Initial Compromise
Description
Attackers exploited exposed AI inference endpoints lacking authentication to gain unauthorized access.
Related CVEs
CVE-2026-7482
CVSS 9.1An out-of-bounds heap read in Ollama's model quantization pipeline allows unauthenticated attackers to upload specially crafted files, leading to process memory leaks including sensitive data.
Affected Products:
Ollama Ollama – All versions prior to 1.0.0
Exploit Status:
exploited in the wildCVE-2026-42271
CVSS 8.8A command injection vulnerability in LiteLLM allows unauthenticated remote attackers to execute arbitrary commands via crafted input to specific endpoints.
Affected Products:
BerriAI LiteLLM – All versions prior to 1.84.0
Exploit Status:
exploited in the wildCVE-2026-49468
CVSS 9.8An authentication bypass vulnerability in LiteLLM allows unauthenticated remote attackers to access protected management endpoints without credentials.
Affected Products:
BerriAI LiteLLM – All versions prior to 1.84.0
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Obtain Capabilities: Artificial Intelligence
Query Public AI Services
Cloud Infrastructure Discovery
Valid Accounts
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Maintain an inventory of system components
Control ID: 6.4.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Asset Management
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
Exposed AI endpoints enable attackers to hijack LLM infrastructure for offensive operations without authentication, requiring enhanced egress security and zero trust segmentation.
Information Technology/IT
Cloud misconfiguration vulnerabilities in Ollama and LiteLLM endpoints allow threat actors to weaponize autonomous penetration testing frameworks against client infrastructure.
Computer/Network Security
Security firms face direct targeting as attackers leverage exposed AI agents for reverse-engineering and penetration testing, bypassing traditional security controls entirely.
Internet
Internet-facing AI services with default configurations become attack vectors for agentic AI operations, requiring immediate visibility controls and authentication enforcement measures.
Sources
- Attackers Seize Exposed AI Endpoints to Power Offensive Opshttps://www.darkreading.com/cloud-security/attackers-hijack-exposed-ai-endpoints-power-offensive-opsVerified
- Ollama vulnerability highlights danger of AI frameworks with unrestricted accesshttps://www.csoonline.com/article/4168584/ollama-vulnerability-highlights-danger-of-ai-frameworks-with-unrestricted-access.htmlVerified
- LiteLLM vulnerability under active attack, CISA warns (CVE-2026-42271)https://www.helpnetsecurity.com/2026/06/09/litellm-vulnerability-under-active-attack-cisa-warns-cve-2026-42271/Verified
- CVE-2026-49468 – Authentication Bypass – LiteLLM prior to 1.84.0https://www.ionix.io/threat-center/cve-2026-49468/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit unauthorized access and lateral movement within the AI infrastructure, thereby reducing the attacker's ability to exploit and disrupt services.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Implementing Aviatrix CNSF would likely limit unauthorized access by enforcing identity-based policies at every workload boundary.
Control: Zero Trust Segmentation
Mitigation: Zero Trust Segmentation would likely constrain the attacker's ability to escalate privileges by enforcing strict access controls and limiting communication paths.
Control: East-West Traffic Security
Mitigation: East-West Traffic Security would likely limit lateral movement by monitoring and controlling internal traffic between workloads.
Control: Multicloud Visibility & Control
Mitigation: Multicloud Visibility & Control would likely constrain the establishment of command and control channels by providing comprehensive monitoring and policy enforcement across cloud environments.
Control: Egress Security & Policy Enforcement
Mitigation: Egress Security & Policy Enforcement would likely limit data exfiltration by controlling and monitoring outbound traffic from workloads.
Implementing Aviatrix Zero Trust CNSF would likely reduce the scope of service disruption and data manipulation by containing the attacker's activities within a limited segment of the network.
Impact at a Glance
Affected Business Functions
- AI Model Hosting
- Data Processing
- API Services
Estimated downtime: 7 days
Estimated loss: $50,000
Potential exposure of sensitive data including system prompts, user messages, and environment variables.
Recommended Actions
Key Takeaways & Next Steps
- • Implement robust authentication mechanisms for all AI inference endpoints to prevent unauthorized access.
- • Apply Zero Trust Segmentation to restrict AI agents' privileges and limit their access to necessary resources only.
- • Enhance East-West Traffic Security to monitor and control lateral movements within the network.
- • Deploy Multicloud Visibility & Control solutions to detect and respond to anomalous activities in real-time.
- • Establish Egress Security & Policy Enforcement to prevent unauthorized data exfiltration through AI endpoints.



