TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

GreyNoise

Threat Actors Actively Targeting LLMs

2026-01-08 · Read original ↗

ATT&CK techniques detected

2 predictions
T1595.002Vulnerability Scanning
62%
"##shell ), cve - 2023 - 1389, and over 200 other vulnerabilities. combined observations exceed 4 million sensor hits. assessment : professional threat actor conducting reconnaissance. the infrastructure overlap with established cve scanning operations suggests this enumeration fe…"
T1588.006Vulnerabilities
55%
"##shell ), cve - 2023 - 1389, and over 200 other vulnerabilities. combined observations exceed 4 million sensor hits. assessment : professional threat actor conducting reconnaissance. the infrastructure overlap with established cve scanning operations suggests this enumeration fe…"

Summary

Our Ollama honeypot infrastructure captured 91,403 attack sessions between October 2025 and January 2026. Buried in that data: two distinct campaigns that reveal how threat actors are systematically mapping the expanding surface area of AI deployments.