Lumen Black Lotus Labs · October 7, 2026

PoeLLM: exposed AI services become mining and scanning infrastructure

Why it matters

Lumen’s Black Lotus Labs describes a campaign targeting exposed AI and development services, including LiteLLM, Ollama, Gotenberg and Gitea. Infected hosts run cryptocurrency miners and can become scanners or exploit servers. The malware derives command-and-control addresses from words in a GitHub-hosted poem, letting the operator redirect bots by changing that document. This is a parsing and lookup mechanism, not evidence that a live language model controls each bot. The report provides infrastructure indicators and sample analysis, while some proposed initial-access paths remain inferred.

My takeaway: Inventory internet-facing AI services and their administrative endpoints, patch exposed components, and investigate mining processes together with outbound scanning. Use the published indicators as leads, then verify host compromise and persistence; blocking one command-and-control address does not remove the malware.
Keep exploring

More curated notes connected through AI Engineering and Agent Security.

OWASP GenAI Security Project · guide

OWASP Top 10 for Agentic Applications for 2026

OWASP's community guide organizes agentic-system risk into ten categories, including goal hijacking, tool misuse, identity and privilege abuse, memory poisoning, insecure inter-agent communication, cascading failures, and rogue-agent behavior. It provides a shared taxonomy and mitigation starting point rather than a certification checklist or evidence that a deployed system is secure.

Microsoft Security Blog · guide

AI vulnerability research: measure reproducible findings and completed fixes

Microsoft’s FORGE account describes the work between a model’s vulnerability claim and a useful repair: reusable builds, duplicate removal, reachability checks, project-specific verification, reproducible triggers and regression tests. Structured rejection reasons help improve later searches. The useful operational measure is the flow of findings that survive verification and reach a fix, rather than the number of candidates generated. Reported successful-case costs exclude parts of screening, failed attempts and human work, so they are not the total cost of operating this pipeline.

OpenAI News · framework

Frontier training safety cases: connect evidence to enforced pause and rollback controls

OpenAI proposes training-run safety cases combining alignment evaluations, containment and monitoring with explicit operational ownership. Concrete measures include immutable transcripts, held-out incident tests, checks for evaluation gaming, response deadlines and fail-closed monitoring. Independent internal challenge, leadership vetoes and tracking downstream uses support stopping a run and reversing affected work. The article describes recommendations still being implemented, rather than audited proof that every safeguard already operates or that residual risk has been eliminated.