OAST is described as a cybersecurity tool/attack tool that threat actors use to exploit misconfigured proxy servers in order to access paid Large Language Model (LLM) services without proper authorization.
Overview
OAST is described as a cybersecurity tool/attack tool that threat actors use to exploit misconfigured proxy servers in order to access paid Large Language Model (LLM) services without proper authorization. It underscores how proxy misconfigurations can be weaponized to bypass access controls and billing, highlighting a notable attack vector in AI service abuse.
Related Threat Clusters
-
Insights on 2025 Web Hacking Techniques and LLM Impact for 2026
James Kettle from PortSwigger discusses the top web hacking techniques of 2025 and anticipates the influence of large language models (LLMs) on future vulnerabilities. He emphasizes the importance of having a robust…
2 articles · Updated April 28, 2026 -
Hackers Exploit Misconfigured Proxies to Access LLM Services
Threat actors have been targeting misconfigured proxy servers to gain unauthorized access to commercial large language model (LLM) services. This campaign, which began in late December 2025, has seen over 91,000 attack…
4 articles · Updated January 9, 2026
Recent Intelligence Reports
- Top 10 Web Hacking Techniques of 2025 and a Hint for 2026 – James Kettle – ASW #380 — Scworld · April 28, 2026
- Hackers target misconfigured proxies to access paid LLM services — Bleepingcomputer · January 9, 2026