1 comments

  • WantonQuantum an hour ago

    Reading through the article, it seems that the exploited vulnerability is "open source AI systems and services. Most of the victims were running vulnerable, internet-facing versions of LiteLLM and Ollama. Additionally, hundreds of victims were running Gotenberg, a PDF converter, and software development platform Gitea."

    The poetry is just a way of obfuscating the current IP address of the botnet control server stored in an otherwise vanilla fork of the nodejs.org website on github.

    Despite the article saying that it uses "an AI jailbreak technique that turns harmful prompts into poems to trick LLMs into bypassing safety guardrails", I can't see anything that implies this is true.

    I could be wrong - it's poorly written article.