Hackers hijack exposed LLM endpoints in “Bizarre Bazaar” operation

Hackers hijack exposed LLM endpoints in “Bizarre Bazaar” operation Source: BleepingComputer www.bleepingcomputer.com/news/secu… Researchers reported an active campaign targeting exposed or weakly authenticated large language model (LLM) service endpoints to monetize unauthorized access to AI infrastructure. Pillar Security said its honeypots logged more than 35,000 attack sessions over 40 days, and assessed the activity as one of the first “LLMjacking” operations attributed to a specific actor.

Edward Kiledjian @ekiledjian