
- GreyNoise logged 91,000 attack sessions against exposed AI systems between Oct 2025 and Jan 2026
- Campaigns included tricking servers into “phoning home” and mass probing to map AI models
- Malicious actors targeted misconfigured proxies, testing OpenAI, Gemini, and other LLM APIs at scale
Hackers are targeting misconfigured proxies in order to see if they can break into the underlying Large Language Model (LLM) service, experts have warned.