This week ·
Exposed AI server operators
How they got in, as reported. A system left reachable from the internet.
← All items this week- Date
- 7 Oct 2026
- Place
- South Korea
- Who
- Exposed AI server operators
- The way in
- Exposed service
- Source
- BleepingComputer
01 · What was reported
What was reported.
A cryptomining campaign dubbed PoeLLM compromised more than 3,400 servers across the United States and Western Europe. Attackers targeted exposed and poorly configured AI services and tools such as LiteLLM, Gotenberg, and Ollama to...
The way in, as the source states it: a system left reachable from the internet.
02 · What we check for it
What we check for it.
Services reachable from the internet that should not be.
03 · Source
Source.
Source: BleepingComputer ↗This page repeats what the source reported, with its date. It says nothing about any firm that is not named in it.