# unauthenticated Ollama

Published articles for unauthenticated Ollama.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## LLMjacking evolved: Attackers are using stolen AI compute to build offensive agentic tools

DevFeed: [LLMjacking evolved: Attackers are using stolen AI compute to build offensive agentic tools](<https://devfeed.tech/articles/llmjacking-evolved-attackers-are-using-stolen-ai-compute-to-build-offensive-agentic-tools-53244.md>)

Original publisher: [Read original article](<https://webflow.sysdig.com/blog/llmjacking-evolved-attackers-are-using-stolen-ai-compute-to-build-offensive-agentic-tools>)

Author: Michael Clark

Published: 2026-06-17T00:00:00Z

Content type: news

Language: en

Sources: [Sysdig](<https://devfeed.tech/sources/sysdig-blog.md>)

Topics: [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [Hacking](<https://devfeed.tech/topics/hacking.md>), [Ollama](<https://devfeed.tech/topics/ollama.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Local AI](<https://devfeed.tech/topics/local-ai.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Self-hosted](<https://devfeed.tech/topics/self-hosted.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [agentic-ai-attack](<https://devfeed.tech/tags/agentic-ai-attack.md>), [agentic-threat-actor](<https://devfeed.tech/tags/agentic-threat-actor.md>), [ai-agent-hacking](<https://devfeed.tech/tags/ai-agent-hacking.md>), [ai-compute-theft](<https://devfeed.tech/tags/ai-compute-theft.md>), [ai-infrastructure-security](<https://devfeed.tech/tags/ai-infrastructure-security.md>), [ai-pipeline-attack](<https://devfeed.tech/tags/ai-pipeline-attack.md>), [ai-powered-cyberattack](<https://devfeed.tech/tags/ai-powered-cyberattack.md>), [ai-supply-chain-risk](<https://devfeed.tech/tags/ai-supply-chain-risk.md>), [autonomous](<https://devfeed.tech/tags/autonomous.md>), [autonomous-exploitation](<https://devfeed.tech/tags/autonomous-exploitation.md>), [autonomous-offensive-ai](<https://devfeed.tech/tags/autonomous-offensive-ai.md>), [blind-sql-injection-ai](<https://devfeed.tech/tags/blind-sql-injection-ai.md>), [build](<https://devfeed.tech/tags/build.md>), [cloud-ai-security](<https://devfeed.tech/tags/cloud-ai-security.md>), [compute](<https://devfeed.tech/tags/compute.md>), [credential-extraction-ai](<https://devfeed.tech/tags/credential-extraction-ai.md>), [credentials](<https://devfeed.tech/tags/credentials.md>), [exploits](<https://devfeed.tech/tags/exploits.md>), [exposed-ollama-server](<https://devfeed.tech/tags/exposed-ollama-server.md>), [generative-ai-threat](<https://devfeed.tech/tags/generative-ai-threat.md>), [hacking](<https://devfeed.tech/tags/hacking.md>), [llm-abuse](<https://devfeed.tech/tags/llm-abuse.md>), [llm-red-team-abuse](<https://devfeed.tech/tags/llm-red-team-abuse.md>), [llm-security-risk](<https://devfeed.tech/tags/llm-security-risk.md>), [llmjacking](<https://devfeed.tech/tags/llmjacking.md>), [model-server-exposure](<https://devfeed.tech/tags/model-server-exposure.md>), [offensive-ai-agent](<https://devfeed.tech/tags/offensive-ai-agent.md>), [ollama](<https://devfeed.tech/tags/ollama.md>), [ollama-security](<https://devfeed.tech/tags/ollama-security.md>), [port-11434](<https://devfeed.tech/tags/port-11434.md>), [proof-of-concept-exploit-generation](<https://devfeed.tech/tags/proof-of-concept-exploit-generation.md>), [security](<https://devfeed.tech/tags/security.md>), [self-hosted](<https://devfeed.tech/tags/self-hosted.md>), [self-hosted-ai-security](<https://devfeed.tech/tags/self-hosted-ai-security.md>), [sysdig-threat-research-team](<https://devfeed.tech/tags/sysdig-threat-research-team.md>), [sysdig-trt](<https://devfeed.tech/tags/sysdig-trt.md>), [unauthenticated-ollama](<https://devfeed.tech/tags/unauthenticated-ollama.md>), [vapt-framework](<https://devfeed.tech/tags/vapt-framework.md>), [vaptb3gin](<https://devfeed.tech/tags/vaptb3gin.md>)

### AI overview

Sysdig Threat Research Team researchers describe an evolution of LLMjacking in which a threat actor used an exposed Ollama model server as the reasoning engine for an automated, multi-stage offensive security tool. The tool scans targets, matches vulnerabilities, generates proof-of-concept exploits, and attempts compromise, while the model makes decisions throughout the process.

### Source excerpt

Sysdig TRT caught a threat actor using a stolen Ollama server to power an autonomous, multi-stage offensive hacking tool -- live, in development, and in full detail.