Today we are joined by Crystal Morin, Senior Cybersecurity Strategist, and Michael Clark, Senior Director of Threat Research, at Sysdig, sharing their work on "LLMjacking evolved: Attackers are using stolen AI compute to build offensive agentic tools." The Sysdig Threat Research Team observed an attacker abusing an exposed, unauthenticated Ollama server as the “brain” for an automated offensive security tool.
The AI-powered framework can fingerprint services, identify vulnerabilities, craft exploits, extract credentials, and orchestrate attacks toward command execution, with researchers capturing the tool while it was still under active development. The activity highlights how LLMjacking is evolving from simply stealing AI compute for profit into using stolen model capacity to build increasingly autonomous offensive capabilities. Research Saturday
Today we are joined by Crystal Morin, Senior Cybersecurity Strategist, and Michael Clark, Senior Director of Threat Research, at Sysdig, sharing their work on "LLMjacking evolved: Attackers are using stolen AI compute to build offensive agentic tools." The Sysdig Threat Research Team observed an attacker abusing an exposed, unauthenticated Ollama server as the “brain” for an automated offensive security tool.
The AI-powered framework can fingerprint services, identify vulnerabilities, craft exploits, extract credentials, and orchestrate attacks toward command execution, with researchers capturing the tool while it was still under active development. The activity highlights how LLMjacking is evolving from simply stealing AI compute for profit into using stolen model capacity to build increasingly autonomous offensive capabilities. Research Saturday
Cybersecurity News

Week that Was

CyberWire Daily

Daily Briefing

CyberWire Daily

Story

Caveat

Daily Briefing

Caveat

AI Security Brief

Hacking Humans
This week, we’re celebrating a pretty big milestone: 400 episodes of Hacking Humans! Along the way, we’ve shared hundreds of stories, scams, lessons, and plenty of memorable Catch of the Days—and we couldn’t have made it this far without you.
To everyone who has listened, written in with a story, sent us a Catch of the Day, or simply learned to be a little more suspicious of that weird text message: thank you for being part of 400 episodes of Hacking Humans. We’re glad you’re here to celebrate with us. And now, after 400 episodes, there’s really only one thing left to do: get back to the scams.
This week, hosts of N2K CyberWire Maria Varmazis and Dave Bittner alongside Joe Carrigan are discussing the latest in social engineering scams, phishing schemes, and criminal exploits that are making headlines. Dave covers celebrity podcast impersonation scams, where fraudsters use personal details, convincing AI-generated personas, and fake production teams to build trust with potential guests. Maria looks at a rental scam that cost a San Francisco renter $18,600 after scammers copied a legitimate apartment listing, showed him the property, and convinced him they were the landlord. Joe discusses new research showing that younger people can be just as vulnerable to scams as older victims, particularly when they're navigating things like jobs, apartments, online shopping, and their first financial accounts. Our Catch of the Day comes from a scammer who apparently discovered the hard way that sometimes the scammer can get scammed. 
CyberWire Daily

Story