Rogue LLM Endpoint Found Exploiting Free AI Services

A researcher discovered a compromised internet-exposed honeypot that was repurposed to provide free large language model (LLM) backends, then used for malicious activities.

Bottom line: Security teams must monitor for suspicious activity related to free LLM services and verify the integrity of their infrastructure.

What's happening: A researcher discovered an internet-exposed honeypot, labeled with sought-after model names, and incorporated into infrastructure used by the researchers at DeepMind and others to provide "free" LLM backends.

What to do: CISOs should review their infrastructure for potential misconfigurations and ensure that any free LLM services used are from trusted vendors, such as Hugging Face, and have a robust security posture.

Source: SANS Internet Storm Center