cd /news/ai-policy/threat-actors-are-posing-as-ai-crawl… · home topics ai-policy article
[ARTICLE · art-116709] src=helpnetsecurity.com ↗ pub= topic=ai-policy verified=true sentiment=↓ negative

Threat actors are posing as AI crawlers to hunt for exposed credentials

Threat actors are disguising automated scanning as traffic from AI crawlers operated by OpenAI, Anthropic, Google, Perplexity and other companies while searching websites for exposed credentials and configuration files, according to GreyNoise. Researchers noted that nothing in a request proves the crawler's identity, as any program can announce itself as ClaudeBot or Googlebot.

read1 min views1 publishedAug 31, 2026

Attackers are disguising automated scanning as traffic from AI crawlers operated by OpenAI, Anthropic, Google, Perplexity and other companies while searching websites for exposed credentials and configuration files, according to GreyNoise. (Source: GreyNoise) “Every program that visits a website announces itself in one line of the request. Chrome says it is Chrome. Googlebot says it is Googlebot. Anthropic’s crawler says it is ClaudeBot. Nothing in the request itself proves any of it is true,” researchers … More

The post Threat actors are posing as AI crawlers to hunt for exposed credentials appeared first on Help Net Security.

── more in #ai-policy 4 stories · sorted by recency
── more on @greynoise 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/threat-actors-are-po…] indexed:0 read:1min 2026-08-31 ·