ExtraHop® Closes Enterprise Data Center Blind Spots with new 400 Gbps sensor

Search
  • Solutionschevron right
  • Industrieschevron right
  • Platformchevron right
  • Resourceschevron right
  • Customerschevron right
  • Companychevron right

How Open-Weight Models Are Reshaping the Cyber Threat Landscape

Share blog icon

Back to top

Back to top

September 16, 2026

How Open-Weight Models Are Reshaping the Cyber Threat Landscape

Artificial intelligence has introduced a structural shift in enterprise risk, creating unmonitored attack paths that defenders are only beginning to trace. Most executive security discussions remain stuck on defensive perimeter logic: how to prevent hosted AI tools from being hijacked.

That framing misses the broader reality. Threat actors aren't just attempting to bypass external model safeguards; they are running open-weight models natively within their own attack chains — executing stealth campaigns without security oversight, no API telemetry, and no account to suspend.

Open-Weight Use Removes Technical Skill Barriers for Threat Actors

Constructing a multi-stage exploit chain historically required sophisticated engineering skills and dedicated operator teams. Open-weight models collapse those operational hurdles overnight.

In June 2026, Sysdig's Threat Research Team captured a threat actor wiring a misconfigured, unauthenticated Ollama server into an automated offensive security tool. The exposed open-weight model acted as the reasoning engine for a pipeline that scanned a target, matched it to known vulnerabilities, wrote proof-of-concept exploits, and attempted break-ins, with the model making the decisions at every step. Because the model ran on an exposed server outside any vendor's controls, there was no SaaS vendor logging API requests, no rate limiting, and no central account to suspend. Sysdig intercepted the framework while it was still in testing.

The same skill collapse is showing up with commercial AI. Between January 11th and February 18th, 2026, Amazon Threat Intelligence tracked a financially motivated actor who used multiple commercial generative AI services to compromise more than 600 FortiGate appliances across more than 55 countries.

There was no vulnerability exploitation: the actor scanned for exposed management ports and logged in with weak, reused single-factor credentials, while AI generated the tooling, attack plans, and operational reporting. Amazon describes a hands-on operator of low-to-medium skill that leaned on AI at every phase and stalled when the automation failed; Team Cymru later tied the same infrastructure to CyberStrikeAI, an open-source AI offensive security platform.

The point stands either way: one actor, whether running a local model or renting one, now operates at the speed and reach of a much larger team, forcing emergency patching, credential revocation, and forensic remediation across dozens of global enterprises.

Architectural Gaps That Prevent Security Tools From Detecting Open-Weight AI

Conventional defensive architectures rely on a fundamental premise: enterprise software leaves an administrative footprint. Open-weight models shatter that design assumption. Running locally on cloud instances, private servers, or idle GPUs, these engines operate entirely outside external logging frameworks.

When a threat actor misuses a commercial API, the hosting provider can detect anomalous activity and terminate access. Misusing an open-weight model on a private compute instance leaves no administrative paper trail to follow.

This blind spot creates immediate operational risk. Independent researchers at SentinelLABS and Censys have catalogued roughly 175,000 publicly exposed Ollama servers across more than 130 countries, each one a free, unattributed reasoning engine for anyone who finds it. The Sysdig case shows what happens next: an adversary found one such server, confirmed it would answer, and pointed an automated exploitation pipeline at it.

Comparing Recent AI-Augmented Threat Campaigns

Loading table...

While the operational footprints differ, both incidents underscore the same structural reality: AI engines, whether self-hosted or commercial, let threat actors automate complex campaigns beyond the reach of traditional oversight.

The Broader Pattern Behind Both Cases

According to the ExtraHop 2026 Global Threat Landscape Report, 85% of organizations have already experienced a security incident, data exposure, or near-miss rooted in an AI system. The most common AI-related incident patterns:

  • 40% of organizations were targeted by AI-enhanced external attacks focused on automated reconnaissance, phishing, or lateral movement.
  • 38% of organizations suffered compromised AI identity or session theft.
  • 36% of organizations reported third-party or supply-chain security incidents involving AI infrastructure.

Adversaries are no longer using AI as an occasional force multiplier; they are embedding local models as persistent command and control engines throughout the attack lifecycle.

Questions CISOs Must Address Today

  • Do we maintain complete operational visibility over every self-hosted, open-weight model running across our infrastructure?
  • Can our current controls identify model execution taking place on unmonitored compute?
  • Are security teams equipped to distinguish legitimate developer tool activity from covert model telemetry?
  • If credentials are compromised, do we have detection mechanisms to catch the subsequent lateral movement?
  • What capabilities do we need to intercept automated model workflows while an attack is actively in progress?

Maintaining Core Security Principles Across Evolving Threat Landscapes

An open-weight model requires neither vendor authorization nor an account to operate — it only requires network reachability. Static asset inventories and vendor logs were never built to detect unmonitored local models running on private compute.

However, no AI engine can obfuscate the physical realities of the wire. To gather reconnaissance, move laterally, or execute payloads, model communications must traverse enterprise infrastructure.

While threat actors constantly adapt their tools, network traffic remains an unalterable constant. Countering machine-speed threats requires a modernized architecture aligned across three distinct layers:

When open models operate inside a governed harness and draw from open network context, security teams can verify automated reasoning and disrupt stealth campaigns before impact occurs.

Learn more about why open models require real-time network context in the ExtraHop blog, Open Models Need Open Context, and explore how industry leaders are building open operating standards for autonomous defense on The Agentic SOC Alliance Blog

Discover more

blog image
Blog author
Raja Mukerji

Chief Scientist and Co-Founder

Raja is the Co-Founder and President of ExtraHop. He co-founded ExtraHop with Jesse Rothstein in 2007.

During their time as Senior Software Architects at F5 Networks, Jesse and Raja played key roles in transforming the load balancer into a new device category known as an application delivery controller, creating a new market in the process. Aware of the massive amount of information that was passing over the network, they realized they could harness gains in processing power to extract valuable real-time insights from this data in motion. Thus, in 2007, the ExtraHop platform was born.

Share
LinkedIn logoX logoFacebook logo
Key Takeaways
  • Threat actors deploy self-hosted open-weight models on private infrastructure to bypass traditional vendor logging and account controls.
  • Open-weight models collapse technical skill barriers, enabling single threat actors to execute multi-stage exploit chains at scale.
  • Traditional security controls fail to detect self-hosted AI because open-weight models leave no administrative or API footprint.
  • Threat actors increasingly embed local AI models as persistent command engines across the entire intrusion lifecycle.
  • Network traffic remains the unalterable constant required to detect stealth activity from unmonitored AI models.

Explore related articles

Experience RevealX NDR for Yourself

Schedule a demo