Join Nostr
2026-09-08 05:33:51 GMT

Thomas Roccia :verified: on Nostr: 🧐 When attackers expose their LLM interface, they expose part of their ...

🧐 When attackers expose their LLM interface, they expose part of their infrastructure and potentially much more!

Unit 42 recently released a threat report that shows how a self hosted NextChat instance, SOCKS5 relays, scripts and reused certificates could be used as a pivot point in your threat research.

In a recent campaign they discovered an exposed NextChat interface used to interact with different models.

The hosted LLM provided all the information needed to extract the Active Directory database, but the infrastructure was accessible to anyone without authentication, exposing the attackers playbook, prompt history and malicious scripts.

Even threat actors are hiring rookies! 😅

Report: https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/