CVE
CVE-2021-29441
Nacos is a platform designed for dynamic service discovery and configuration and service management. In Nacos before version 1.4.1, when configured to use authentication (-Dnacos.core.auth.enabled=true) Nacos uses the AuthFilter servlet filter to enforce authentication. This filter has a backdoor that enables Nacos servers to bypass this filter and therefore skip authentication checks. This mechanism relies on the user-agent HTTP header so it can be easily spoofed. This issue may allow any user
Exploitation IoCs 21
Domain adminapi[.]tippusoni[.]in
Domain protonmail[.]com
Domain xs[.]xxooonline[.]eu[.]cc
Filename .bd.php
Filename .brq-*.php
Filename .wp-log.php
Filename back.bat
Filename back.txt
Filename bai.bat
Filename check_paths.py
Filename deploy_implant.py
Filename dll.zip
Filename down.php
Filename prcc1.rar
Filename sss.ashx
Filename svchosts.exe
Filename up.ashx
Filename user.bat
IP 137[.]175[.]93[.]126
IP 139[.]180[.]197[.]150
IP 43[.]108[.]17[.]80
MITRE ATT&CK TTPs 17
T1021 T1027 T1053.003 T1059.001 T1059.003 T1068 T1071 T1071.001 T1075 T1078 T1082 T1083 T1090 T1133 T1190 T1485 T1490
Remote Services
Lateral Movement
Obfuscated Files or Information
Defense Evasion
Cron
Execution
PowerShell
Execution
Windows Command Shell
Execution
Exploitation for Privilege Escalation
Privilege Escalation
Application Layer Protocol
Command And Control
Web Protocols
Command And Control
T1075
Valid Accounts
Defense Evasion
System Information Discovery
Discovery
File and Directory Discovery
Discovery
Proxy
Command And Control
External Remote Services
Persistence
Exploit Public-Facing Application
Initial Access
Data Destruction
Impact
Inhibit System Recovery
Impact
Source Articles
UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations
Cisco Talos identified a Chinese-speaking threat actor, UAT-10147, conducting a global campaign targeting Windows and Linux web servers in government, education, media, technology, and gaming sectors. The actor leverages publicly disclosed vulnerabilities for initial access, including CVE-2022-27925, CVE-2021-23758, and CVE-2019-18935, and uses AI-driven tooling to automate exploitation, reconnaissance, payload generation, and validation. Post-compromise, the actor deploys malware such as QuasarRAT, Gh0stCringe, and SPECTRE, establishes persistence via scheduled tasks and rogue user accounts, and uses AI-generated scripts to refine attacks and bypass defenses. A misconfigured command-and-control server at 139.180.197[.]150 exposed operational details, including a target list of 170,000 URLs and AI-assisted attack workflows.
talos Aug 20, 2026
Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites
A cybercrime group operating under the name WP-SHELLSTORM left a server exposed for 22 days, revealing their infrastructure and tools used to backdoor over 5,700 WordPress and Joomla sites. The group exploited known vulnerabilities in plugins like Breeze (CVE-2026-3844) and Joomla JCE (CVE-2026-48907), deploying webshells such as down.php and using the SNOWLIGHT dropper to install the VShell backdoor. The exposed server contained logs, exploit scripts, and target lists of over 1.4 million domains, highlighting a financially motivated, Chinese-speaking crew with poor operational security.
hacker-news Jul 10, 2026
JadePuffer ransomware used AI agent to automate entire attack
JadePuffer ransomware represents the first documented case of a ransomware operation fully automated by a large language model (LLM) agent. The AI-driven attack exploited CVE-2025-3248 in Langflow to gain initial access, then performed reconnaissance, credential theft, lateral movement, and encryption autonomously. The agent adapted to failures in real time, demonstrating human-like operational resilience and rapid iteration. It encrypted 1,342 Nacos configuration items and left a ransom note with a Proton Mail contact and a Bitcoin address, though the encryption likely used AES-128-ECB rather than AES-256 as claimed.
bleeping-computer Jul 4, 2026