The Self-Expanding Stolen Inference Supply Chain: An AI Agent Harvesting and Re-Serving LLM Access, (Fri, Sep 11th)
2026-09-12T13:23:42Z•c551617a87f427ac588281c11c421167c2765699d5e1de2e968d9338f47c4656
AI agentsLLM API abuseMicrosoft Patch TuesdayMikroTikProxmox VERedtail malwareSSH authentication bypassaccount farmingactive exploitationcritical vulnerabilitiesinference supply chainpersistencevulnerability scanning
What happened
SANS Internet Storm Center feed covering active exploitation and vulnerability activity, including a critical MikroTik SSH authentication bypass with attackers adding persistent accounts, scanning targeting outdated Proxmox VE 7 systems, a large September 2026 Microsoft Patch Tuesday, Redtail payload analysis, and an AI-assisted operation harvesting and reselling LLM inference access through compromised or fraudulently created accounts and exposed gateways.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- c551617a87f427ac588281c11c421167c2765699d5e1de2e968d9338f47c4656
- Enrichment time
- 2026-09-12T13:23:42Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.