Monitoring agentic emergent misalignment in the wild - a word of caution and a methodology proposal
A closer look at Ollama model-pull SSRF targeted activity in the wild
A closer look at custom-code guardrail sandbox-escape (CVE–2026-40217) activity in the wild
A closer look at api_base SSRF (CVE-2024-6587) activity in the wild, and its nested variant
Inside mass discovery and model-probing reconnaissance campaigns that are mapping LLM backend servers in the wild
Threat actors attempting to hijack Ollama & LiteLLM endpoints to run pentesting agents, tools and web reverse-engineering
What we can learn from observing real attacks, made by real adversaries
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
