Today we are joined by Crystal Morin, Senior Cybersecurity Strategist, and Michael Clark, Senior Director of Threat Research, at Sysdig, sharing their work on "LLMjacking evolved: Attackers are using stolen AI compute to build offensive agentic tools." The Sysdig Threat Research Team observed an attacker abusing an exposed, unauthenticated Ollama server as the “brain” for an automated offensive security tool.

The AI-powered framework can fingerprint services, identify vulnerabilities, craft exploits, extract credentials, and orchestrate attacks toward command execution, with researchers capturing the tool while it was still under active development. The activity highlights how LLMjacking is evolving from simply stealing AI compute for profit into using stolen model capacity to build increasingly autonomous offensive capabilities.

The research and executive brief can be found here:

LLMjacking evolved: Attackers are using stolen AI compute to build offensive agentic tools

Podden och tillhörande omslagsbild på den här sidan tillhör N2K Networks. Innehållet i podden är skapat av N2K Networks och inte av, eller tillsammans med, Poddtoppen.