DNS tunneling and HTTPS requests bypass traditional network allow-lists to leak sensitive data. LLMs can encode secrets into seemingly benign traffic, rendering simple domain filtering ineffective. Security practitioners must shift toward deep packet inspection and behavioral monitoring. Relying on static lists creates a false sense of security against sophisticated model-driven exfiltration.