October 8, 2026 at 07:33AM

■■■■□ The “PoeLLM” malware uses and targets exposed AI/LLM and open-source services. It primarily affects vulnerable internet-facing deployments such as LiteLLM, Ollama, Gotenberg and Gitea, with possible targeting of Ivanti Sentry.

https://www.lumen.com/blog/en-us/canto-incognito-tracking-the-poellm-malware