Unsecured AI Ollama Hosts Found Exposed Online

Massive exposure of 175,000 Ollama AI hosts with tool-calling capabilities exploited by Operation Bizarre Bazaar.

  • Security researchers identified approximately 175,000 publicly accessible Ollama AI hosts across 130 countries, most with high-risk capabilities.
  • Nearly half of these exposed systems support tool-calling, enabling them to execute code and interact with external systems without proper authentication.
  • An active criminal operation, dubbed Operation Bizarre Bazaar, is already scanning for and selling access to these vulnerable AI endpoints.

A new joint investigation by SentinelOne SENTINELLABS and Censys has uncovered a massive, unmanaged global network of exposed Ollama AI infrastructure, creating a serious security blind spot for organizations. This sprawling network of 175,000 unique hosts operates outside standard platform guardrails, with the largest concentration located in China.
Consequently, the publicly accessible nature of these systems poses new security concerns requiring novel defensive approaches. Nearly 50% of observed hosts are configured with tool-calling capabilities, meaning they can execute code and access APIs. Researchers Gabriel Bernadett-Shapiro and Silas Cutler added that this “fundamentally alter[s] the threat model.”
Meanwhile, the risk of infrastructure abuse, termed LLMjacking, has moved from theory to practice. A separate report from Pillar Security this week details an active campaign dubbed Operation Bizarre Bazaar, where attackers scan for and sell access to these endpoints. This operation has been traced to a threat actor named Hecker.
The decentralized and often residential nature of this infrastructure complicates traditional governance and monitoring. Therefore, defenders must treat externally accessible LLMs with the same stringent controls as other critical infrastructure.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -

Latest News

Hong Kong CEO Touts City as Web3 Hub, Stablecoin Licenses Soon

Hong Kong's Chief Executive, John KC Lee, has declared the city's goal to become...

Ray Dalio Warns of Government Control via CBDCs

Ray Dalio warns CBDCs grant governments sweeping transaction monitoring and policy enforcement powers.He argues...

LSEG, Apex Group to tokenize private funds by 2026

First paragraph: A compelling hook combining who, what, when, where.LSEG and Apex Group launch...

Justin Sun’s Ex Says X Account Suspended Over Mass Reports

An X account belonging to Justin Sun's alleged former girlfriend, Zeng Ying, was suspended...

Dollar Could Fall 10% on Aggressive Fed Cuts

State Street strategists warn the US dollar could fall up to 10% if the...

Must Read

How To Buy a Handshake Domain: A Step-by-Step Guide

Handshake Domains | Benefits | Drawbacks | How To Buy | Supported BrowsersIn this step-by-step guide, I am going to show you how to...
🔥 #AD Get 20% OFF any new 12 month hosting plan from Hostinger. Click here!