CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →
← Back to the live brief
NOTABLENATOB2threat

ReliaQuest: LLM-driven agents run most of an intrusion through one unauthenticated Spring Batch job-submission feature on Apache Tomcat, from in-process JavaScript to SYSTEM in under 24 hours

ReliaQuest: AI agents took a Tomcat server to SYSTEM in under a day through an exposed job-submission feature

Analysis

ReliaQuest says the attacker needed no zero-day and no new malware: an internet-facing Apache Tomcat application used Spring Batch, in which a task definition names the code to run, and accepted and ran task descriptions without a login (ReliaQuest, 2026-10-07). The decisive step was submitting tasks that invoked Nashorn, the JavaScript engine in the application's Java environment, so the code ran inside the application with its account privileges and created no child process until a shell was spawned later; results came back through deliberately triggered error messages, in fixed 1,800-byte chunks reassembled over hundreds of requests (ReliaQuest, 2026-10-07). The application's configuration files held plaintext credentials with SQL Server sysadmin rights; the attacker enabled xp_cmdshell, found SeImpersonatePrivilege, uploaded PrintSpoofer and GodPotato in base64 fragments through the same channel and reached SYSTEM when the first tool failed on file permissions and the second worked (ReliaQuest, 2026-10-07). With SYSTEM it saved the SAM, SYSTEM and SECURITY registry hives for offline extraction, created two local administrator accounts and deleted only one, and removed artifacts after the actions that produced them (ReliaQuest, 2026-10-07).

The agent-driven reading rests on a live, unauthenticated Cairn agent-orchestration dashboard (an open-source platform for coordinating AI agents; no source says whether it is the Cairn exploitation engine of Gambit Security's reporting, and it is not Talos' CAIRN toolkit) on the address that sent the opening requests, on command timing (roughly half the gaps five seconds or less), on job names that tracked read offsets and upload parts without a gap, on machine-readable pipe-delimited output, and on payloads whose next version repaired the fault the previous one returned; ReliaQuest says no single indicator establishes it and that it could not determine how many agents ran, which model drove them or how much a person approved (ReliaQuest, 2026-10-07). Submission and collection ran from different addresses, so blocking the submitting address alone would not have stopped retrieval, and the tool assembly is not a fingerprint for any group (ReliaQuest, 2026-10-07).

Cited evidence

The attacker entered through an internet-facing application feature on an Apache Tomcat server that accepted and ran task descriptions without requiring a login.

No single one establishes that an LLM agent was involved; a human directing scripts could produce several of them.

ReliaQuest Threat Research 2026-10-07

Sources1

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.