On June 12, 2026, the Sysdig Threat Research Team (TRT) observed a threat actor using a misconfigured Ollama model server as the reasoning engine for an automated, multi-stage offensive security tool. The post shows how LLMjacking has evolved from stealing AI compute for resale into using that stolen compute to power agentic attack tooling.