The Self-Expanding Stolen Inference Supply Chain: An AI Agent Harvesting and Re-Serving LLM Access, (Fri, Sep 11th)

2026-09-13T19:23:41Z•a92ae1d0e63e60c3dbbad1c2d179bdd1a2b7f1d317b25cdd16eccc203cd3d610
AI agentsAPI abuseLLM access harvestingMicrosoft Patch TuesdayMikroTikProxmox VESSH authentication bypassaccount farmingactive exploitationcredential persistenceinference resale gatewaysvulnerability scanning

What happened

SANS Internet Storm Center entries report an emerging semi-autonomous operation that harvests LLM inference capacity through exposed resale gateways, web flaws, and account farming, then aggregates access behind an attacker-controlled gateway. The feed also highlights active exploitation of an SSH authentication-bypass vulnerability in MikroTik devices, legacy Proxmox VE scanning, and a record Microsoft Patch Tuesday with vulnerabilities exploited in the wild. No specific CVE identifiers are provided in the supplied document.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
a92ae1d0e63e60c3dbbad1c2d179bdd1a2b7f1d317b25cdd16eccc203cd3d610
Enrichment time
2026-09-13T19:23:41Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · The Self-Expanding Stolen Inference Supply Chain: An AI Agent Harvesting and Re-Serving LLM Access, (Fri, Sep 11th) · Baitaphish