AI Is Going Just Great

Category

Data Leakage

Confidential prompts, training data, internal documents, or PII surfacing where they shouldn’t — through the model itself, its logs, or its tools.

← All categories

  1. July 2026

  2. ·5mo agoConcerningModerateollama

    Security scan finds 1,652 Ollama APIs and hundreds of AI agent platforms exposed with no authentication

    intruder.io

    The AI infrastructure we researched is more vulnerable, exposed, open, and misconfigured on average than any other software we've ever investigated.

    Security firm Intruder scanned roughly 1 million internet-exposed AI services and found widespread misconfiguration. Of 5,200+ Ollama APIs reachable online, 1,652 (31%) responded to a simple "hello" prompt with no authentication required. Another 92 Flowise instances exposed full agentic workflows, prompts, and credential lists; 25 Langflow and 24 Open WebUI instances similarly lacked any login gate. The researchers noted this is a sharp rise from Cisco's finding of 18% misconfigured Ollama instances in September 2025.

    Among the exposed systems: a Flowise instance laying out the entire business logic and personality prompts of a commercial chatbot service, multiple NSFW "goon-bots" powered by Claude that leaked their API keys in plaintext, and Ollama endpoints clearly designed for processing sensitive medical data and cloud infrastructure management. Of all models identified across the exposed servers, 518 were wrapping paid frontier models from Anthropic, OpenAI, Google, DeepSeek, and others — freely usable by anyone who found them. The researchers also discovered new, undisclosed remote code execution vulnerabilities in at least one popular AI project during their analysis.

    Security / AbuseData Leakage
  3. ·1mo agoConcerningMajorxai

    Grok Build CLI Was Silently Uploading Users' Entire Codebases — Including Files It Was Told to Ignore

    theverge.com

    "including files it was told not to open and secrets deleted from history"

    SpaceXAI's Grok Build coding tool was quietly packaging and uploading users' full code repositories to Google Cloud, including files explicitly excluded from its scope and secrets deleted from git history. Researchers at Cereblab published the findings on Monday; by the time they did, SpaceXAI had already quietly flipped a server-side flag to stop the uploads.

    Independent security researcher Dr. Lukasz Olejnik described the data retention as "excessive," noting that what could have left users' machines includes "proprietary source code, information about security vulnerabilities, personal data, infrastructure details, [and] credentials." Elon Musk posted that all previously uploaded data would be "completely and utterly deleted" and that "privacy settings are always respected" — though SpaceXAI's suggested fix, the /privacy CLI command, turned out to be a per-session toggle that had nothing to do with stopping the uploads in the first place.

    Data LeakageSecurity / Abuse
  4. — end of timeline —