ReliaQuest: LLM-driven agents run most of an intrusion through one unauthenticated Spring Batch job-submission feature on Apache Tomcat, from in-process JavaScript to SYSTEM in under 24 hours
ReliaQuest: AI agents took a Tomcat server to SYSTEM in under a day through an exposed job-submission feature
Analysis
ReliaQuest says the attacker needed no zero-day and no new malware: an internet-facing Apache Tomcat application used Spring Batch, in which a task definition names the code to run, and accepted and ran task descriptions without a login (ReliaQuest, 2026-10-07). The decisive step was submitting tasks that invoked Nashorn, the JavaScript engine in the application's Java environment, so the code ran inside the application with its account privileges and created no child process until a shell was spawned later; results came back through deliberately triggered error messages, in fixed 1,800-byte chunks reassembled over hundreds of requests (ReliaQuest, 2026-10-07). The application's configuration files held plaintext credentials with SQL Server sysadmin rights; the attacker enabled xp_cmdshell, found SeImpersonatePrivilege, uploaded PrintSpoofer and GodPotato in base64 fragments through the same channel and reached SYSTEM when the first tool failed on file permissions and the second worked (ReliaQuest, 2026-10-07). With SYSTEM it saved the SAM, SYSTEM and SECURITY registry hives for offline extraction, created two local administrator accounts and deleted only one, and removed artifacts after the actions that produced them (ReliaQuest, 2026-10-07).
The agent-driven reading rests on a live, unauthenticated Cairn agent-orchestration dashboard (an open-source platform for coordinating AI agents; no source says whether it is the Cairn exploitation engine of Gambit Security's reporting, and it is not Talos' CAIRN toolkit) on the address that sent the opening requests, on command timing (roughly half the gaps five seconds or less), on job names that tracked read offsets and upload parts without a gap, on machine-readable pipe-delimited output, and on payloads whose next version repaired the fault the previous one returned; ReliaQuest says no single indicator establishes it and that it could not determine how many agents ran, which model drove them or how much a person approved (ReliaQuest, 2026-10-07). Submission and collection ran from different addresses, so blocking the submitting address alone would not have stopped retrieval, and the tool assembly is not a fingerprint for any group (ReliaQuest, 2026-10-07).
Cited evidence
The attacker entered through an internet-facing application feature on an Apache Tomcat server that accepted and ran task descriptions without requiring a login.
No single one establishes that an LLM agent was involved; a human directing scripts could produce several of them.
Sources1
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.