AI Pulse · Under the Radar
The play
Spoofed bot traffic is spiking, so if you whitelist AI crawlers, add IP verification or you're opening the door to scanners.
Someone is running coordinated vulnerability scans across thousands of websites right now, and they’re disguising the traffic to look like legitimate AI crawlers from Anthropic and Google. A Hacker News thread with over 150 upvotes reports a sharp spike in the past week, with attackers specifically hunting for exposed credentials in newer AI coding tool deployments.
The attackers are spoofing user-agents like ClaudeBot and Googlebot, which means your server logs might show what looks like normal AI crawler traffic when it’s actually someone probing for weaknesses. The targets appear to be AI-assisted development tools that teams have spun up quickly, often without hardening security first. If your company is running any AI coding assistants, code generation tools, or internal LLM deployments, you’re in the crosshairs.
This matters because those tools often have access to your codebase, API keys, and internal documentation. A compromised deployment can hand over everything. The spoofing angle is clever because many teams whitelist AI crawlers or don’t scrutinize that traffic closely. You need to verify that ClaudeBot or Googlebot traffic is actually coming from Anthropic or Google IP ranges, not just trusting the user-agent string.
If you’ve deployed any AI dev tools in the past few months, audit them now. Check for default credentials, exposed endpoints, and whether they’re sitting behind proper authentication. Review your server logs for unusual patterns, even if they claim to be known bots. This is exactly the kind of threat intelligence that should flow into something like an AI command centre, where you can monitor what’s hitting your infrastructure and cross-reference it against known attack patterns in real time. The thread is still developing, so treat this as an active situation, not a resolved incident.
Free daily email
Get this every morning.
This brief is one item from today's AI Pulse, the short daily read we run for ourselves on what is actually happening in AI. Subscribe free and it lands in your inbox each morning.
Free daily email
Subscribe to the daily AI Pulse
One short read every morning on what is actually happening in AI. Free.
You are in
Your first AI Pulse lands tomorrow morning. Keep an eye on your inbox.