Bleepingcomputer Hackers Exploit Misconfigured Proxies to Access LLM Services
Article Content
Browse articles
Threat actors have been targeting misconfigured proxy servers to gain unauthorized access to commercial large language model (LLM) services. This campaign, which began in late December 2025, has seen over 91,000 attack sessions recorded, indicating a systematic effort to map AI deployment vulnerabilities.
Ask AI about this cluster
Answers cite the sources they use
Updated 182d ago How this analysis works
More articles in this cluster (4)
Following this threat?
Track React2Shell, Alibaba and CVE-2023-1389 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Multiple CVEs Expose Vulnerabilities in Cybersecurity Tools and Applications A series of vulnerabilities have been reported affecting various cybersecurity tools and applications. Notable among them is CVE-2024-51482, a blind SQL injection vulnerability in ZoneMinder, allowing attackers to execute arbitrary SQL commands on the database server. CVE-2026-22557, a path traversal vulnerability in…
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…