Home / Companies / NeuralTrust / Blog / Post Details
Content Deep Dive

GreyNoise Confirmed: Active Campaigns are Systematically Probing Enterprise LLMs

Blog post from NeuralTrust

Post Details
Company
Date Published
Author
Alessandro Pignati
Word Count
1,101
Company Posts That Month
12
Language
English
Hacker News Points
-
Post removed?
No
Summary

Between October 2025 and January 2026, GreyNoise's honeypot infrastructure detected 91,403 coordinated attack sessions targeting LLM endpoints, marking a significant shift from theoretical to actual AI risks. These attacks comprised two major campaigns: the SSRF Campaign, which exploited model pull functionality to force outbound connections through vulnerabilities in Ollama Model Pulls and Twilio Webhooks, and the Enumeration Campaign, which systematically probed over 73 model endpoints to identify misconfigured proxies. The attackers, using sophisticated tactics, aim to inventory exposed infrastructure to exploit AI systems, treating them with the same precision used for legacy infrastructures like VPNs and CI/CD servers. This shift emphasizes the critical need for organizations to adopt proactive security measures, such as rigorous egress filtering, continuous monitoring, and AI Red Teaming, to protect their AI infrastructure from being fully mapped and exploited by threat actors. As AI becomes integral to enterprise operations, platforms like NeuralTrust are highlighted for offering essential tools for runtime protection and governance, ensuring AI systems remain secure and trustworthy in the face of advanced reconnaissance and exploitation efforts.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
LLM 9 4,658 798 239 +8%
AI Guardrails 3 360 127 55 -16%
MCP 2 3,702 403 162 -31%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.