insidejob
AML.T0049 Realized ATT&CK T1190 ↗

Exploit Public-Facing Application

Tactic: Initial Access

This technique has been observed in real-world attacks on AI systems.

Adversaries may attempt to take advantage of a weakness in an Internet-facing computer or program using software, data, or commands in order to cause unintended or unanticipated behavior. The weakness in the system can be a bug, a glitch, or a design vulnerability. These applications are often websites, but can include databases (like SQL), standard services (like SMB or SSH), network device administration and management protocols (like SNMP and Smart Install), and any other applications with Internet accessible open sockets, such as web servers and related services.