
Analysis of Large-Scale Attacks Targeting LocalAI Infrastructure and Exfiltration of Sensitive Data from Thai Military
Oasis Security analyzed attacker-server tools and callback logs showing unauthenticated LocalAI instances used for remote code execution, including compromise of a desktop LocalAI workstation in Thailand and theft of AWS ECS credentials.









![Sliver Threat Intelligence: Infrastructure, Trends, and Key Insights [March 2026 - May 2026]](/blog-images/sliver/fig_0.jpg)





























