Urgent.News

What's breaking now, across thousands of outlets.

Tech

Poetry is the new AI security threat as PoeLLM malware infects 3K+ servers

Quoth the LLM, 'More and more'

Poetry is the new AI security threat as PoeLLM malware infects 3K+ servers

A suspected Italian cybercriminal has infected over 3,000 servers with a malware known as PoeLLM since April. The malware targets enterprise AI infrastructure to mine cryptocurrency and expand its botnet. This is the first documented case of "adversarial poetry," a technique that turns harmful prompts into poems to trick large language models (LLMs) into bypassing safety guardrails.

The attackers may have used a poem as a "perfect vehicle for hiding an important message" that remains unnoticed by security professionals. PoeLLM malware has been active primarily in the US and Western Europe, scanning for vulnerable internet-facing versions of LiteLLM, Ollama, Gotenberg, and Gitea. The malware abuses these open-source tools and can turn compromised systems into vulnerability scanners and exploit servers.

The threat originates from an Italian-speaking criminal, named Canto Incognito, whose GitHub repository contains a poem titled "On the Nature of Connection." The poem contains hidden commands that the malware uses to discover new command-and-control (C2) servers. As enterprises increasingly use AI in their operations, the attack surface grows, making them more vulnerable to such threats.

Written by urgent.news from The Register's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Also reported by 1 other outlet

Read the original at theregister.com →

More in Tech

App Report: All That Jazz

Sometimes, putting these columns about intriguing macOS and iOS apps together feels a little like improvisational jazz — I’m not always sure where this is going or how it’s going to wind up, but…

More from Wednesday 7 October →