The Worm That Rents Nothing and Steals Everything
Two years of AI-attack visibility work assumed the adversary rents intelligence from a provider that can watch the abuse and revoke the key; this prototype deletes that assumption at the design level.
What to do
Enumerate and tag every GPU-capable host into the CMDB with an owner and network segment this sprint, including CI runners and developer workstations with discrete cards, then stream DCGM/nvidia-smi utilisation, VRAM allocation and CUDA context UID into the SIEM.
Ship EDR detections this sprint for unauthorised local inference runtimes on non-ML hosts (ollama, llama.cpp, vLLM, text-generation-inference, transformers loading local weights) plus internal file transfers over 1GB to hosts with no ML role.
Run a tabletop this quarter for a decentralised agentic worm with no sinkhole, no takedown and no stable indicator, and pre-authorise mass segment isolation with a named signatory before the exercise ends.