AI Security

Autonomous AI Agents Exploited to Harvest and Resell Stolen LLM API Access

FORTSECURE GLOBAL· 2026-09-13🛰 SANS Internet Storm Center
#AI Security#API Security#Cyber Risk#Cloud Security

Cybersecurity researchers have detected an automated campaign utilizing semi-autonomous AI coding agents to discover misconfigured LLM gateways, harvest API credentials, and bundle unauthorized inference capacity into rogue proxy networks.

Autonomous Agents Powering the Shadow LLM Supply Chain

Recent intelligence highlights a sophisticated threat model where attackers leverage semi-autonomous AI coding agents to automate offensive operations at scale. Rather than manually scanning for exposed interfaces, threat actors deploy intelligent agents instructed to discover misconfigured Large Language Model (LLM) resale gateways and unhardened AI proxy endpoints. Once identified, these agents exploit standard web vulnerabilities and engage in automated account farming to siphon active API keys and unauthorized inference tokens.

After obtaining access, the agent automatically benchmarks the harvested credentials to verify their inference bandwidth and latency. Confirmed functional tokens are then consolidated behind a unified proxy architecture operated by the attacker. This allows malicious actors to build a self-expanding, stolen AI supply chain, offering discounted model access on the cybercrime underground while legitimate enterprise accounts absorb the astronomical compute costs.

Strategic Recommendations for Securing AI Infrastructure

To safeguard corporate AI assets from unauthorized exploitation, organizations should adopt modern application and API security controls:

  • Implement Granular API Quotas and Rate Limiting: Enforce strict consumption limits per API key and token to prevent high-volume automated harvesting.
  • Continuous Telemetry and Anomaly Detection: Monitor prompt patterns and outbound network traffic from LLM endpoints for atypical query distributions indicative of proxying operations.
  • Enforce Strict Access Controls: Integrate OAuth 2.0 with mutual TLS (mTLS) for all internal inference gateways, eliminating reliance on static bearer tokens.
  • Ephemeral Credential Management: Leverage automated key rotation schedules to ensure exposed keys expire rapidly before they can be weaponized.

แหล่งที่มา: SANS Internet Storm Center เผยแพร่ครั้งแรก: Fri, 11 Sep 2026 14:40:32 GMT บทความต้นฉบับ: อ่านต้นฉบับ

Source Attribution

แหล่งที่มา: SANS Internet Storm Center

เผยแพร่ครั้งแรก: Fri, 11 Sep 2026 14:40:32 GMT

บทความต้นฉบับ: https://isc.sans.edu/diary/rss/33332

อ่านบทความต้นฉบับ ↗
ถูกใจบทความนี้

* Facebook / LinkedIn ไม่อนุญาตให้ใส่ข้อความให้ล่วงหน้า — กดปุ่มจะคัดลอกข้อความให้ก่อน เปิดหน้าแชร์แล้ววาง (paste) ได้เลย พรีวิวการ์ดจะแสดงอัตโนมัติเมื่อวางลิงก์

← กลับไปหน้า Blog