Hacker News
Scan of 1 Million Exposed AI Services Reveals Worst Security of Any Software Category — 31% of Ollama Instances Respond Without Auth
The Intruder security team scanned 2 million hosts and identified 1 million exposed AI services, finding the AI infrastructure was 'more vulnerable, exposed, and misconfigured than any other software' they've investigated. Of 5,200+ Ollama API servers tested, 31% responded to prompts without authentication, with 518 instances wrapping premium frontier models from Anthropic and OpenAI using hardcoded API keys. Widespread misconfigurations include insecure Docker setups, applications running as root, and agent management platforms (n8n, Flowise) left internet-facing without authentication — exposing real user conversations and company tooling.
↳ Follow the thread