In June 2026, security researchers at Sysdig observed a threat actor exploiting a misconfigured, unauthenticated Ollama model server to power “VAPT,” a purpose-built framework that uses AI-driven decision-making to scan targets, match vulnerabilities, generate exploit code, and attempt intrusions with minimal human involvement. Ollama listens on port 11434 with no authentication enabled by default, and researchers have catalogued roughly 175,000 publicly exposed instances worldwide. The framework chained several open-weight and commercial models together to automate reconnaissance, SQL-injection crafting, secret extraction, and privilege escalation, illustrating stolen AI compute being repurposed directly as offensive infrastructure.