SophiaX
🔍
LIVE
· New victim: cipher.systems — m3rx· New victim: International Chemical Co. — Barracuda· New victim: M****n — payoutsking· New victim: Applied Composites — Storm· New victim: Magna Legal Services — Storm· New KEV: CVE-2026-65660 · Microsoft· New KEV: CVE-2026-87902 · WordPress· New KEV: CVE-2026-67279 · MikroTik· New KEV: CVE-2026-71362 · Adobe· New KEV: CVE-2026-5430 · WSO2· New victim: 4,078 new IOCs ingested in last 24h cipher.systems — m3rx· New victim: International Chemical Co. — Barracuda· New victim: M****n — payoutsking· New victim: Applied Composites — Storm· New victim: Magna Legal Services — Storm· New KEV: CVE-2026-65660 · Microsoft· New KEV: CVE-2026-87902 · WordPress· New KEV: CVE-2026-67279 · MikroTik· New KEV: CVE-2026-71362 · Adobe· New KEV: CVE-2026-5430 · WSO2· 4,078 new IOCs ingested in last 24h

Qilin

💰 eCrimeMotivation: financialLast active: 2026-09-23First seen: 2026-04-01
3
linked CVEs
Targeted industries
Agriculture and Food ProductionBusiness ServicesConstructionConsumer ServicesEducationEnergyFinancial ServicesHealthcareHospitality and TourismManufacturingNot FoundPublic SectorTechnologyTelecommunicationTransportation/Logistics
Targeted regions
AEARATAUBEBRCACHCLCOCZDEDKESFIFJFRGBGRHKHUIEILINITJPKRLAMAMDMXMYNHNZPHPRPSPTPYRUSASESGSISKTHTRTWUAUSVEVN
Wiz Threat Research deployed honeypots across AI and ML services including LiteLLM, Flowise, LangChain, Langflow, ChromaDB, and Ollama, observing sustained attack activity over 90 days. Three distinct attack patterns emerged: exploitation of Internet-facing MCP servers for remote code execution through authentication bypass and command injection vulnerabilities; blind prompt injection attacks against AI agent frameworks using out-of-band DNS callbacks to confirm execution; and AI-native post-exploitation techniques adapted to AI infrastructure internals, including extracting master keys from Python module state and staging cryptominers in framework-specific directories. Attackers demonstrated deep knowledge of AI tooling internals, targeting credential concentration points where proxies hold multiple provider keys, and exploiting agent reachability to execute instructions embedded in requests. The campaigns primarily deployed XMRig cryptominers, leveraging framework-specific paths and processes for camoufl...
Source: misp_galaxy · Collected: 2026-09-23
⚡ Vulnerabilities & Exploits3 CVEs
threat_actor_cve → cves / exploits.cve_ids
CVE-2026-42271
suspected

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.74.2 to before version 1.83.7, two endpoints used to preview an MCP server before saving it — POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list — accepted a full server configuration in the request body, including the command, args, and env fields used by the stdio transport. When called with a stdio configuration, the endpoints attempted to connect, which spawned the supplied command as a subprocess on the proxy host with the privileges of the proxy process. The endpoints were gated only by a valid proxy API key, with no role check. Any authenticated user — including holders of low-privilege internal-user keys — could therefore run arbitrary commands on the host. This issue has been patched in version 1.83.7.

CVSS 8.8
KEV
CVE-2026-59822
suspected

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, LiteLLM's MCP Streamable HTTP endpoint allowed an unauthenticated attacker to use a fabricated Authorization header to trigger an OAuth2 passthrough fallback path that replaced failed LiteLLM key validation with an empty UserAPIKeyAuth() object, allowing requests to reach MCP tooling without a valid LiteLLM key. This issue is fixed in version 1.84.0.

CVSS 8.2
KEV
CVE-2026-48710
suspected

Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw HTTP path while `request.url` is rebuilt from the `Host` header, a malformed header could make `request.url.path` differ from the path that was actually requested. Middleware and endpoints that apply security restrictions based on `request.url` (rather than the raw `scope` path) could therefore be bypassed. Users should upgrade to a version greater than or equal to version 1.0.1, which validates the `Host` header against the grammar of RFC 9112 §3.2 / RFC 3986 §3.2.2 when constructing `request.url` and falls back to `scope["server"]` for malformed values.

CVSS 6.5
KEV
🔍 Detection Coverage0 Sigma
Derived from linked CVEs — not a direct actor match
No Sigma rules mapped via this actor's CVEs yet.
🧬 YaraComing soon
🛰️ Infrastructure & IOCs6
ip94.26.106.29—2026-08-28
urlhttp://185.62.1.8/mon/mon.zip'—2026-08-28
ip185.84.98.85—2026-08-28
domaincrazyeltonproxy.top—2026-08-28
domain1710.rwlp.be—2026-08-28
ip185.62.1.8—2026-08-28
📰 Threat Intel Coverage0
Digest reports mentioning this actor (incl. aliases)
No threat intel digest coverage found.