CVE
CVE-2021-29441
Nacos is a platform designed for dynamic service discovery and configuration and service management. In Nacos before version 1.4.1, when configured to use authentication (-Dnacos.core.auth.enabled=true) Nacos uses the AuthFilter servlet filter to enforce authentication. This filter has a backdoor that enables Nacos servers to bypass this filter and therefore skip authentication checks. This mechanism relies on the user-agent HTTP header so it can be easily spoofed. This issue may allow any user
Exploitation IoCs 8
Domain protonmail[.]com
Domain xs[.]xxooonline[.]eu[.]cc
Filename .bd.php
Filename .brq-*.php
Filename .wp-log.php
Filename down.php
IP 137[.]175[.]93[.]126
IP 43[.]108[.]17[.]80
MITRE ATT&CK TTPs 17
T1021 T1027 T1053.003 T1059.001 T1059.003 T1068 T1071 T1071.001 T1075 T1078 T1082 T1083 T1090 T1133 T1190 T1485 T1490
Remote Services
Lateral Movement
Obfuscated Files or Information
Defense Evasion
Cron
Execution
PowerShell
Execution
Windows Command Shell
Execution
Exploitation for Privilege Escalation
Privilege Escalation
Application Layer Protocol
Command And Control
Web Protocols
Command And Control
T1075
Valid Accounts
Defense Evasion
System Information Discovery
Discovery
File and Directory Discovery
Discovery
Proxy
Command And Control
External Remote Services
Persistence
Exploit Public-Facing Application
Initial Access
Data Destruction
Impact
Inhibit System Recovery
Impact
Source Articles
Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites
A cybercrime group operating under the name WP-SHELLSTORM left a server exposed for 22 days, revealing their infrastructure and tools used to backdoor over 5,700 WordPress and Joomla sites. The group exploited known vulnerabilities in plugins like Breeze (CVE-2026-3844) and Joomla JCE (CVE-2026-48907), deploying webshells such as down.php and using the SNOWLIGHT dropper to install the VShell backdoor. The exposed server contained logs, exploit scripts, and target lists of over 1.4 million domains, highlighting a financially motivated, Chinese-speaking crew with poor operational security.
hacker-news Jul 10, 2026
JadePuffer ransomware used AI agent to automate entire attack
JadePuffer ransomware represents the first documented case of a ransomware operation fully automated by a large language model (LLM) agent. The AI-driven attack exploited CVE-2025-3248 in Langflow to gain initial access, then performed reconnaissance, credential theft, lateral movement, and encryption autonomously. The agent adapted to failures in real time, demonstrating human-like operational resilience and rapid iteration. It encrypted 1,342 Nacos configuration items and left a ransom note with a Proton Mail contact and a Bitcoin address, though the encryption likely used AES-128-ECB rather than AES-256 as claimed.
bleeping-computer Jul 4, 2026