LIVE · cybersecurity feed
Live wire
Acronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEsCVE-2026-76461 · U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogHackers target WordPress sites via third-party WooCommerce pluginCVE-2026-51990 · Hackers exploit Tencent app flaw to deploy GrayRabbit malwareCVE-2026-42016 · CISA Adds 5 Exploited Flaws in Artifactory, ScreenConnect, RouterOS to KEVCVE-2026-85102 · Dutch NCSC: Critical Check Point VPN flaws exploitation is imminentAI Enables Mass Generation of Personalized Fraud EmailsCVE-2026-85706 · Critical GitLab Vulnerability Exploited in Internet-Wide ProbesCVE-2025-66516 · Metasploit Wrap Up: This One Goes to Sixteen!
breach

The AI Supply Chain Has a Security Problem, and Much of It Is Sitting on the Open Internet

Researchers found 36,769 exposed AI endpoints, but only 2% had an HTTP authentication gate. Running AI locally is supposed to give organizations more control. Models, prompts and documents stay on infrastructure they manage instead of being sent to a third-party cloud. But that advantage disappears quickly when the infrastructure itself is exposed to the public […]

zeroday.news ·

A recent study has revealed a significant cybersecurity vulnerability within the self-hosted artificial intelligence (AI) ecosystem, identifying tens of thousands of exposed AI endpoints that lack basic authentication. Researchers from Mysterium VPN found 36,769 such endpoints, including model servers, agent-building platforms, and vector stores, all publicly accessible via internet scanning indexes. A striking 98% of these endpoints did not present an HTTP authentication challenge, indicating a widespread absence of network-layer security.

The findings highlight a critical gap in the security posture of organizations opting to run AI models locally, a strategy often chosen for greater control over data and infrastructure. However, this advantage is negated when the underlying infrastructure is directly exposed to the internet without proper safeguards.

Among the most prevalent exposed systems was Open WebUI, a popular front-end for local large language models (LLMs), with 18,529 reachable instances identified. Only one of these instances exhibited an HTTP authentication challenge. Other widely exposed platforms included vLLM (4,880 endpoints, three with authentication), LocalAI (150 endpoints, none with authentication), and llama.cpp (69 endpoints, none with authentication).

A particularly concerning discovery involved Ollama servers. Mysterium VPN researchers were able to confirm anonymous access directly from the service response itself, as an exposed Ollama server returns the text "Ollama is running" from its root endpoint without requiring credentials. They identified 6,935 hosts displaying this fingerprint, with 6,046 explicitly returning an HTTP 200 response. This level of exposure not only allows unauthorized parties to view installed models but also to utilize the owner's hardware for text generation, leading to resource abuse, commonly termed "LLMjacking."

The scope of this issue may be even broader. A separate study conducted by SentinelOne and Censys in January identified approximately 175,000 publicly exposed Ollama hosts across 130 countries, with nearly half supporting tool-calling capabilities that could execute code or interact with external systems. Mysterium's figures, derived from a different scanning source and stricter fingerprinting, are considered a lower bound.

Beyond the models themselves, the study also focused on exposed agent builders and workflow platforms, finding 5,223 such instances. These systems, including Flowise, n8n, ComfyUI, Dify, RAGFlow, Langflow, and Open WebUI Pipelines, pose a heightened risk because they often integrate AI models with other critical company infrastructure. Automation workflows on these platforms can store sensitive information such as OpenAI API keys, database credentials, Slack tokens, webhook secrets, and CRM passwords.

Flowise serves as a prime example, with 1,341 reachable instances found by Mysterium, none of which presented an HTTP authentication challenge. This is particularly concerning given a critical Flowise vulnerability, CVE-2026-40933, which allows an authenticated attacker to execute arbitrary commands via the MCP adapter. While Flowise addressed this flaw in version 3.1.0, the combination of internet exposure and potential vulnerabilities significantly increases the attack surface for credential compromise.

The problem extends beyond software vulnerabilities. Research by GitGuardian in August uncovered n8n API tokens exposed in public GitHub commits. They identified 4,576 unique tokens linked to 1,255 hostnames. Of the 896 reachable instances tested, 321 accepted at least one of these leaked tokens, demonstrating that attackers can gain access to workflows and connected systems without exploiting a software flaw, simply by using compromised credentials. This underscores a broader challenge for AI security, particularly as organizations increasingly adopt automation platforms.

breachaicloud
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

September Patch Tuesday part 2?

vulnerabilityhigh

Acronis warns of actively exploited flaw in its cPanel backup plugin

Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]

vulnerabilitycritical

Oracle September 2026 Critical Security Patch Update addresses 672 CVEs

Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates. Key Takeaways The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates 104 issues (15.5% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at

CVE-2026-76461critical

U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco Secure Email Gateway flaw, tracked as CVE-2026-76461 (CVSS score of 9,8), to its Known Exploited Vulnerabilities (KEV) catalog. Cisco disclosed a critical zero-day CVE-2026-76

patch

Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer's website and pushed updates that created a hidden user account. [...]

ai

Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow?

Microsoft agreed to adopt guardrails and privacy standards for its AI in schools, as negotiated with the American Federation of Teachers. The post Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow? appeared first on SecurityWeek.