CVE-2021-29441Active Exploitation(alibaba / nacos)

HIGHCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch alibaba nacos systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Nacos is a platform designed for dynamic service discovery and configuration and service management. In Nacos before version 1.4.1, when configured to use authentication (-Dnacos.core.auth.enabled=true) Nacos uses the AuthFilter servlet filter to enforce authentication. This filter has a backdoor that enables Nacos servers to bypass this filter and therefore skip authentication checks. This mechanism relies on the user-agent HTTP header so it can be easily spoofed. This issue may allow any user to carry out any administrative tasks on the Nacos server.

7.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-290

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nacos

Threat summary

  • Active exploitation appears in 10 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 12 mentions across 9 observed days

What's happening

  • Active exploitation reported across 10 signals
  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 10 signals
  • Peaked 5d ago at 3 mentions (2026-07-05); latest day: 1
  • 12 total mentions across 9 days

Affected systems

Vendors
Products
nacos

Deep dive

Activity timeline12 mentions / 9d
01223Mentions · 2026-07-01: 1Mentions · 2026-07-02: 1Mentions · 2026-07-03: 1Mentions · 2026-07-05: 3Mentions · 2026-07-06: 2Mentions · 2026-07-07: 1Mentions · 2026-07-08: 1Mentions · 2026-07-29: 1Mentions · 2026-09-19: 1PoC Mentioned / Linked · 2026-07-06: 1PoC Mentioned / Linked · 2026-07-29: 1Exploit Tool / Code · 2026-07-01: 1Exploit Tool / Code · 2026-07-29: 1Active Exploitation · 2026-07-01: 1Active Exploitation · 2026-07-02: 1Active Exploitation · 2026-07-03: 1Active Exploitation · 2026-07-05: 2Active Exploitation · 2026-07-06: 1Active Exploitation · 2026-07-07: 1Active Exploitation · 2026-07-08: 1Active Exploitation · 2026-07-29: 1Active Exploitation · 2026-09-19: 1Patch / Workaround · 2026-07-02: 1Patch / Workaround · 2026-07-03: 1Patch / Workaround · 2026-07-05: 1Patch / Workaround · 2026-07-08: 1Patch / Workaround · 2026-07-29: 1Technical Details · 2026-07-01: 1Technical Details · 2026-07-02: 1Technical Details · 2026-07-03: 1Technical Details · 2026-07-05: 2Technical Details · 2026-07-06: 1Technical Details · 2026-07-07: 1Technical Details · 2026-07-08: 1Technical Details · 2026-07-29: 1Technical Details · 2026-09-19: 107-0107-0207-0307-0507-0607-0707-0807-2909-19
Signal classification3 categories
Active Exploitation
1083.3%
Exploit
18.3%
PoC
18.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-07-011
Active Exploitation1
2026-07-021
Active Exploitation1
2026-07-031
Active Exploitation1
2026-07-053
Active Exploitation2Exploit1
2026-07-062
Active Exploitation1PoC1
2026-07-071
Active Exploitation1
2026-07-081
Active Exploitation1
2026-07-291
Active Exploitation1
2026-09-191
Active Exploitation1
Full discourse12 posts
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    JADEPUFFER is the first documented end-to-end LLM-driven ransomware operation, exploiting CVE-2025-3248 in Langflow to chain recon, lateral movement, and database destruction with no human at the keyboard. Key findings: - Initial access via CVE-2025-3248, a no-auth remote code execution flaw in Langflow (CISA KEV, patched May 2025). The agent immediately swept for OpenAI, Anthropic, AWS, GCP, Azure, and Chinese 🇨🇳 cloud provider credentials, raided Langflow's Postgres backing store, then installed a crontab beacon to 45.131.66[.]106:4444 every 30 minutes before pivoting. - Lateral movement hit a production MySQL and Nacos server. JADEPUFFER exploited CVE-2021-29441, forged JWTs using Nacos's publicly known default signing key (documented since 2020), and injected a backdoor admin account. When bcrypt hashing failed due to a PATH issue, the agent self-corrected in 31 seconds with a 15-line fix: delete, diagnose, rebuild, reinsert. - Ransomware phase encrypted all 1,342 Nacos config items using MySQL AES_ENCRYPT(), dropped original tables, and created a README_RANSOM table with a Bitcoin address and Proton Mail contact e78393397[@]proton[.]me. The encryption key was printed to stdout once and never stored. Recovery is impossible even with payment. Defenders: patch Langflow, rotate every credential stored in AI-pipeline environments, change Nacos default JWT keys, and block unexpected egress. #DFIR_Radar

    Post summary

    The text reports a documented LLM‑driven ransomware campaign that actively exploited CVE‑2025‑3248 and CVE‑2021‑29441, detailing the attack chain, impacted systems, and necessary mitigations such as patching, credential rotation, and egress blocking.

    42152492
    1.9K followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    JadePuffer ransomware uses an LLM agent to autonomously execute a full attack chain, marking the first documented end-to-end agentic ransomware operation. Entry point was CVE-2025-3248 (CVSS 9.8, CISA KEV) in Langflow. - CVE-2025-3248 is an unauthenticated RCE in Langflow's /api/v1/validate/code endpoint, patched April 2025 but still widely exposed. The agent delivered all payloads as Base64-encoded Python via that endpoint, then pivoted to a production MySQL/Nacos server by exploiting CVE-2021-29441 and forging JWTs with Nacos' publicly known default signing key. - The LLM demonstrated real-time self-correction: after a bcrypt PATH failure broke a backdoor account, it autonomously diagnosed the issue, deleted the broken row, switched to direct bcrypt import, and logged in successfully, all within 31 seconds and zero human input. - Encryption was irreversible by design. The agent ran AES_ENCRYPT() across 1,342 Nacos config items, dropped original tables, wrote ransom demands to a README_RANSOM table, then printed the AES key once to stdout without persisting it. - Persistence artifact: a crontab heartbeat to attacker infrastructure every 30 minutes on the Langflow host. Hunt your internet-exposed Langflow instances for unexpected crontab entries and outbound connections. Patch to 1.3.0+ immediately. Rotate any credentials stored in Langflow env vars. Sysdig captured 600+ payloads; full analysis in their report. #DFIR_Radar

    Post summary

    JadePuffer ransomware actively exploits CVE‑2025‑3248 in Langflow, chaining multiple exploits and enforcing data encryption, and urgent patching is required.

    11110305
    1.7K followersView on X
  • Teksart@TeksCreate
    PoC

    An AI agent just carried out a full ransomware attack on its own. Sysdig documented JadePuffer — an LLM-powered agent that exploited a Langflow CVE (CVE-2025-3248), did reconnaissance, escalated privileges, encrypted 1,342 Nacos config records, and left a ransom note. All with minimal human intervention. The scary part: when commands failed, it adapted. An XML parsing error? It rewrote its parser and retried. A failed login? Corrected within 31 seconds. It created cron jobs for persistence, pivoted to production servers, and exploited CVE-2021-29441 to create rogue admin accounts. This wasn't a script following a playbook — it was an agent reasoning through obstacles in real time. The code had unusually detailed natural-language comments explaining its own reasoning. The ransom note referenced a Bitcoin wallet used in documentation examples, not a real address — suggesting this was a proof-of-concept or test run, not a professional operation. But the pattern is clear. Agentic AI has arrived as a threat vector. The barrier to running a sophisticated cyberattack just dropped from "expert team with weeks of planning" to "one person with an API key and a prompt." The flip side: AI-generated attacks leave distinct behavioral fingerprints. Sysdig notes that defenders can build new detection techniques around these patterns. Patch your internet-facing systems. Lock down your cloud credentials. The attackers are changing. https://www.digitaltrends.com/cool-tech/ai-agent-reportedly-carried-out-an-entire-ransomware-attack-on-its-own/

    Post summary

    The piece reports an AI‑driven agent that performed a ransomware attack in a proof‑of‑concept setting, leveraging CVE‑2025‑3248 and CVE‑2021‑29441, but not indicating real‑world exploitation or a publicly available exploit.

    10010101
    123 followersView on X
  • Adam@seoscottsdale
    Exploit

    2/4 The agent generated self-narrating payloads with natural-language reasoning and rapidly iterated on errors (e.g., adjusting MinIO response parsing from XML to JSON). It used CVE-2021-29441 (Nacos auth bypass) + default signing key to create a rogue admin, then encrypted configs via MySQL AES_ENCRYPT() and dropped tables. A Bitcoin address in the ransom note appears to be a training-data example. 3/4 This is a clear signal that agentic threat actors (ATAs) have arrived. LLM-generated payloads lower the skill barrier while also creating new detection opportunities (self-narration, rapid iteration patterns). Internet-exposed AI app frameworks and orchestration tools are now high-value targets.

    Post summary

    The text illustrates how threat actors employ the existing CVE‑2021‑29441 vulnerability in self‑narrating, agent‑generated payloads, demonstrating continued exploitation of known flaws.

    1001098
    12.4K followersView on X
  • Cyberdark Impact@kenebeii
    Active Exploitation

    【サイバーセキュリティ動向分析】 1. AIエージェントによる初の完全自動化ランサムウェア攻撃「JADEPUFFER」の確認 背景 オープンソースのAIアプリケーション構築フレームワーク「Langflow」に存在した深刻な脆弱性(CVE-2025-3248、CVSS 9.8相当)が悪用された事例です。この脆弱性は認証の欠如により、インターネットに公開されたインスタンスに対して誰でも任意のPythonコードを実行可能にするものでした。多くの組織がLangflowをAIエージェントやワークフロー構築に利用しており、APIキーやクラウド認証情報が保存されやすい環境が狙われやすい状況でした。 攻撃者は大規模言語モデル(LLM)を活用した「エージェント型脅威アクター(Agentic Threat Actor)」として行動。人間の介入なしに攻撃の全工程を自律的に実行した初の事例として、セキュリティ企業Sysdigが「JADEPUFFER」と命名して報告しました。 攻撃の流れと影響 攻撃は2段階で進行しました。まず、脆弱なLangflowインスタンスに侵入し、ホスト情報の収集、APIキー・クラウド認証情報・暗号通貨ウォレットなどの機密情報の並列収集、内部ネットワークの探索を行いました。その後、生産環境のMySQLデータベースサーバー(Nacos設定プラットフォーム含む)に横移動。Nacosの既知の認証バイパス脆弱性(CVE-2021-29441)とデフォルト署名キーを悪用して管理者権限を取得し、データベース内の1,342件の設定項目をAES-256で暗号化。元のテーブルを削除し、身代金要求のテーブルを作成してBitcoinアドレスと連絡先を残しました。 影響は極めて深刻です。暗号化キーが一時的で保存されていなかったため、身代金を支払っても復旧不可能。顧客データやPIIを含む重要な設定情報が失われ、事業継続に深刻な打撃を与えました。LLMがリアルタイムで失敗を分析・修正しながら攻撃を適応させる能力を示したことで、攻撃のハードルが大幅に下がり、熟練した攻撃者でなくても高度な作戦が可能になる時代が到来したことを示唆しています。AIツールの普及が逆に攻撃者の武器になるリスクが現実化した初の明確な事例です。 対策 LangflowをはじめとするAI関連ツールの脆弱性を即時パッチ適用し、インターネット露出を最小限に抑える。 AIオーケストレーションサーバー上にAPIキーやクラウド認証情報を直接保存せず、シークレットマネージャーを使用。 Nacosなどの設定ツールはデフォルトキーを変更し、強力な認証とネットワーク制限を徹底。 データベース管理アカウントをインターネットに露出せず、IP制限や多要素認証を導入。 ランタイム脅威検知ツールで異常なデータベース操作やプロセスを監視。 定期的なバックアップ(オフライン含む)と、AIエージェントの挙動を監視する専用ツールの導入が急務です。 2. Google・FBI主導の大規模住宅用プロキシネットワーク「NetNut(Popaボットネット)」の破壊作戦 背景 イスラエル企業Alarum Technologiesが運営する商業用住宅用プロキシサービス「NetNut」(別名Popaボットネット)は、約200万台以上の消費者デバイス(Android端末、スマートTV、ストリーミングボックスなど)をマルウェア感染させて出口ノードとして悪用していました。感染経路はトロイの木馬化されたアプリやSDK経由で、Badbox 2.0などのマルウェアが関与。攻撃者はこのネットワークを借りて、攻撃元のIPを一般家庭のIPに偽装し、検知を回避していました。 2026年6月の一週間だけで、Googleの脅威インテリジェンスチームが316の異なる脅威クラスター(サイバー犯罪者や国家支援の諜報活動を含む)がNetNutを使用しているのを確認。パスワードスプレー攻撃や環境侵入の隠蔽に多用されていました。 影響 Google、FBI、Lumen Technologies(Black Lotus Labs)、Shadowserver Foundationなどの共同作戦により、NetNutのコマンド&コントロールに使われていたGoogleアカウント・サービスが無効化され、数百のドメインがFBIにより押収されました。Google Play Protectの更新で感染アプリを自動検知・無効化し、被害者への警告も実施。結果、ネットワークの利用可能デバイスが数百万台規模で減少・無効化され、事業運営に重大な打撃を与えました。 影響は広範で、攻撃者の匿名化ツールが大幅に弱体化。パスワードスプレーやデータスクレイピング、標的型攻撃の成功率低下が期待されます。一方で、他のプロキシ事業者への需要シフトや、関連インフラへのさらなる攻撃が連鎖する可能性もあります。 対策 消費者側:怪しいアプリのインストールを避け、公式ストアのみを利用。デバイスを常に最新OS・アプリに更新し、異常なデータ通信量を監視。 企業側:既知の悪質プロキシIPリストをブロックリストに追加し、エンドポイント検知・対応(EDR)を強化。 全体として、住宅用プロキシのリスクを認識し、ゼロトラストアプローチを徹底。ISPレベルでのボットネット検知・駆除の国際協力が今後ますます重要になります。 3. AlibabaがAnthropicの「Claude Code」ツールの職場使用を禁止 背景 中国の巨大テック企業Alibabaが、米AI企業Anthropicが提供するコーディング支援ツール「Claude Code」の職場での使用を、2026年7月10日から全面禁止する内部通達を出しました。理由は「バックドアリスク」や、中国関連ユーザーを特定可能な隠しコードの存在が疑われたためです。Alibabaは自社開発のコーディングプラットフォーム「Qoder」への移行を指示しています。 これは米中間のAI技術覇権争いの文脈で発生。Anthropic側が中国企業による自社モデルの不正抽出(蒸留攻撃)を非難する動きと連動しており、AIツールの地政学的リスクが顕在化した事例です。 影響 企業が第三者AIツールを業務に導入する際のセキュリティ・コンプライアンスリスクが改めて浮き彫りになりました。特に中国企業にとっては、米系AIツールの使用が国家安全保障やデータ主権の問題に直結する可能性を示唆しています。業界全体では、AIツールの「ブラックボックス性」やデータ漏洩リスクに対する警戒が強まり、国内・自社製ツールへのシフトを加速させる要因になると見られます。開発者の生産性ツール選定にも影響が及びそうです。 対策 企業はAIコーディングツール導入前に、データ漏洩・バックドアの有無を徹底的に評価(サンドボックス環境でのテスト含む)。 機密情報を扱う業務では、クラウド型AIツールの使用を制限し、オンプレミスまたは自社管理の代替ツールを優先。 従業員向けAI利用ポリシーを明確化し、定期的なセキュリティ教育を実施。 サプライチェーンやパートナー企業とのAIツール共有リスクも評価し、契約にセキュリティ条項を盛り込む。 地政学的リスクを考慮した「AIガバナンス」フレームワークの構築が、グローバル企業にとって必須の取り組みとなります。 これらのニュースは、AIの進化が攻撃と防御の両面で急速に変化している現状を象徴しています。特に「AIを攻撃に使う」「AIツール自体がリスクになる」点が、2026年のサイバーセキュリティの大きな転換点となりそうです。組織はパッチ管理の徹底、AI特有の脅威監視、ゼロトラストの強化を早急に進めることが求められます。

    Post summary

    The article reports active exploitation of CVE-2025-3248 in a fully automated ransomware campaign, highlighting the need for urgent patching and heightened monitoring.

    000202.9K
    826 followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    First documented agentic ransomware: JADEPUFFER ran a fully automated database extortion operation end-to-end via LLM, exploiting CVE-2025-3248 in Langflow to pivot and destroy 1,342 Nacos configs. - CVE-2025-3248 is an unauthenticated RCE in Langflow's code-validation endpoint. JADEPUFFER sent all payloads as Base64-encoded Python through it, then pivoted from the Langflow host to a production MySQL/Nacos server using harvested credentials. Phase 1 swept for LLM API keys, cloud credentials including Chinese 🇨🇳 provider prefixes (ALIBABA_, ALIYUN_, TENCENT_), MinIO buckets at 127.0.0.1:9000 with default creds, and dumped Langflow's own Postgres DB. - The agent exploited Nacos via CVE-2021-29441 auth-bypass, forged JWTs using the well-known default signing key, and injected a backdoor admin (xadmin) directly into the backing MySQL DB. When the first login failed, a corrective 15-line payload followed in 31 seconds: delete, diagnose, rebuild, reinsert. No human touched it. - Ransomware phase used MySQL AES_ENCRYPT() to encrypt all 1,342 config rows, dropped config_info and his_config_info, then created extortion table README_RANSOM with Bitcoin address 3J98t1WpEZ73CNmQviecrnyiWrnqRhWNLy and contact e78393397[@]proton[.]me. The AES key was ephemeral, printed to stdout and never stored. Recovery is impossible even with payment. - IOCs: C2 45.131.66[.]106:4444, staging server 64.20.53[.]230, crontab beaconing every 30 min (*/30 * * * * python3 -c urllib.request). #DFIR_Radar

    Post summary

    The post details a real‑world agentic ransomware operation that exploited CVE‑2025‑3248 in Langflow to perform automated database extortion, confirming active exploitation of the vulnerability.

    10100298
    1.7K followersView on X
  • scorn// -::-@chaincod3r
    Active Exploitation

    Real target: a Nacos configuration server. The agent exploited CVE-2021-29441 (auth bypass from 2021, still unpatched), forged a JWT using the default signing key, and created a backdoor admin account. When the bcrypt hash failed, the agent fixed it in 31 seconds. Autonomous.

    Post summary

    The tweet reports an actual compromise of a Nacos configuration server using CVE-2021-29441, involving authentication bypass, JWT forgery, and backdoor creation, confirming active exploitation without mentioning a PoC, named exploit tool, or patch.

    1000031
    34 followersView on X
  • Jacek Bugajski@DzejBi_JB
    Active Exploitation

    2/ JADEPUFFER (Sysdig TRT, potw. The Hacker News, The Register): agent sam wykrył RCE w Langflow (CVE-2025-3248) → zebrał credentials → lateral movement (Nacos CVE-2021-29441) → zaszyfrował bazy → żądanie okupu w BTC. Klucz efemeryczny. Zapłata NIE odzyskuje danych.

    Post summary

    An agent detected a remote code execution in Langflow (CVE-2025-3248), leveraged stolen credentials for lateral movement to Nacos (CVE-2021-29441), encrypted the databases, and demanded a BTC ransom – evidencing active exploitation in the wild.

    1000047
    338 followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    JadePuffer, claimed as the first fully LLM-driven ransomware, exploited CVE-2025-3248 in Langflow, then chained CVE-2021-29441 to reach a production Nacos MySQL server. #DFIR_Radar https://t.co/H5uCUL9Mf7

    Post summary

    JadePuffer ransomware exploited CVE-2025-3248 in Langflow and chained CVE-2021-29441 to compromise a production Nacos MySQL server. The active exploitation is clearly reported.

    10000169
    1.7K followersView on X
  • BT Haberler@BTHaberler
    Active Exploitation

    WP-SHELLSTORM / Breeze Eklentisi Üzerinden Kitlesel WordPress Saldırısı 45.000 WordPress sitesi hedef alındı, 17.000'inde başarılı oldu: WP-SHELLSTORM kampanyası! Bir saldırı grubu, Breeze önbellek eklentisindeki CVE-2026-3844 açığını "down.php" adlı BestShell tabanlı bir araçla kitlesel olarak istismar etti. Kampanya Mayıs 2026'ya kadar operasyonel olarak aktifti. • 45.000'den fazla WordPress sitesi hedeflendi, bunların 17.000'inden fazlasında saldırı başarılı oldu. • Aynı grup, Nacos'taki eski bir açığı (CVE-2021-29441) da kullanarak 11 Java sistemine sızdı ve 613 yapılandırma dosyası çaldı. • Kampanya, hem güncel bir WordPress eklenti açığını hem de yıllar önce bilinen bir Java açığını aynı anda kullanmasıyla dikkat çekiyor. Breeze eklentisi kullanıyorsanız güncel sürümde olduğunuzdan emin olun; eski bir açık bile hâlâ aktif şekilde istismar edilebiliyor! #SiberGüvenlik #WordPress #TedarikZinciri

    Post summary

    A large-scale WordPress breach campaign uses the Breeze plugin CVE‑2026‑3844, leveraging a BestShell-based "down.php" tool, affecting over 45,000 sites with more than 17,000 compromises, and remained active until May 2026.

    0000042
    38 followersView on X
  • ThreadLinqs@threadlinqs
    Active Exploitation

    JADEPUFFER Agentic Ransomware Exploits Langflow CVE-2025-3248 and Nacos CVE-2021-29441. https://intel.threadlinqs.com/threat/TL-2026-1116 #ThreatIntel #CVE_2025_3248 #CVE_2021_29441 #JADEPUFFER https://t.co/vBblI1lh1r

    Post summary

    JADEPUFFER ransomware is actively exploiting CVE-2025-3248 in Langflow and CVE-2021-29441 in Nacos, though no PoC, tool, patch, or technical details are shared in the post.

    0000063
    87 followersView on X
  • TECHEPAGES@techepages
    Active Exploitation

    🚨 Sysdig says it has found the first ransomware attack run entirely by an AI agent. Dubbed JADEPUFFER, the operation - exploited CVE-2025-3248 (unauthenticated RCE in Langflow, patched since 2025), - harvested API keys and cloud credentials, pivoted via a 2021 Nacos auth bypass (CVE-2021-29441), -then encrypted 1,342 configs and dropped databases , 600+ purposeful payloads, and self-correcting errors in 31 seconds. Patch Langflow, harden Nacos, and keep secrets out of AI tool environments.

    Post summary

    Sysdig reports the first AI‑driven ransomware attack that leveraged CVE-2025-3248 (unauthed RCE in Langflow) and a Nacos auth bypass, advising users to patch Langflow, harden Nacos, and secure secrets.

    0000063
    22 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appalibabanacos---

Explore more