Bottom line: Security teams must monitor for suspicious activity related to free LLM services and verify the integrity of their infrastructure.
What's happening: A researcher discovered an internet-exposed honeypot, labeled with sought-after model names, and incorporated into infrastructure used by the researchers at DeepMind and others to provide "free" LLM backends.
What to do: CISOs should review their infrastructure for potential misconfigurations and ensure that any free LLM services used are from trusted vendors, such as Hugging Face, and have a robust security posture.