CVE

CVE-2021-29441

Nacos is a platform designed for dynamic service discovery and configuration and service management. In Nacos before version 1.4.1, when configured to use authentication (-Dnacos.core.auth.enabled=true) Nacos uses the AuthFilter servlet filter to enforce authentication. This filter has a backdoor that enables Nacos servers to bypass this filter and therefore skip authentication checks. This mechanism relies on the user-agent HTTP header so it can be easily spoofed. This issue may allow any user

Exploitation IoCs 21

Domain adminapi[.]tippusoni[.]in
Domain protonmail[.]com
Domain xs[.]xxooonline[.]eu[.]cc
Filename .bd.php
Filename .brq-*.php
Filename .wp-log.php
Filename back.bat
Filename back.txt
Filename bai.bat
Filename check_paths.py
Filename deploy_implant.py
Filename dll.zip
Filename down.php
Filename prcc1.rar
Filename sss.ashx
Filename svchosts.exe
Filename up.ashx
Filename user.bat
IP 137[.]175[.]93[.]126
IP 139[.]180[.]197[.]150
IP 43[.]108[.]17[.]80

MITRE ATT&CK TTPs 17

Source Articles

UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations
Cisco Talos identified a Chinese-speaking threat actor, UAT-10147, conducting a global campaign targeting Windows and Linux web servers in government, education, media, technology, and gaming sectors. The actor leverages publicly disclosed vulnerabilities for initial access, including CVE-2022-27925, CVE-2021-23758, and CVE-2019-18935, and uses AI-driven tooling to automate exploitation, reconnaissance, payload generation, and validation. Post-compromise, the actor deploys malware such as QuasarRAT, Gh0stCringe, and SPECTRE, establishes persistence via scheduled tasks and rogue user accounts, and uses AI-generated scripts to refine attacks and bypass defenses. A misconfigured command-and-control server at 139.180.197[.]150 exposed operational details, including a target list of 170,000 URLs and AI-assisted attack workflows.
talos Aug 20, 2026
Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites
A cybercrime group operating under the name WP-SHELLSTORM left a server exposed for 22 days, revealing their infrastructure and tools used to backdoor over 5,700 WordPress and Joomla sites. The group exploited known vulnerabilities in plugins like Breeze (CVE-2026-3844) and Joomla JCE (CVE-2026-48907), deploying webshells such as down.php and using the SNOWLIGHT dropper to install the VShell backdoor. The exposed server contained logs, exploit scripts, and target lists of over 1.4 million domains, highlighting a financially motivated, Chinese-speaking crew with poor operational security.
hacker-news Jul 10, 2026
JadePuffer ransomware used AI agent to automate entire attack
JadePuffer ransomware represents the first documented case of a ransomware operation fully automated by a large language model (LLM) agent. The AI-driven attack exploited CVE-2025-3248 in Langflow to gain initial access, then performed reconnaissance, credential theft, lateral movement, and encryption autonomously. The agent adapted to failures in real time, demonstrating human-like operational resilience and rapid iteration. It encrypted 1,342 Nacos configuration items and left a ransom note with a Proton Mail contact and a Bitcoin address, though the encryption likely used AES-128-ECB rather than AES-256 as claimed.
bleeping-computer Jul 4, 2026