This page may contain stale information. Last updated: 2026-07-04
Overview
Nacos is an open-source dynamic service discovery and configuration management platform developed by alibaba for cloud microservices. Widely deployed in Chinese cloud environments; backs configuration for distributed applications.
Security Context (July 2026)
- JADEPUFFER attack: Agentic ransomware pivoted from langflow to production MySQL/Nacos server (2026-07-04-jadepuffer-agentic-ransomware)
- Exploited CVE-2021-29441 (auth bypass), default JWT signing key (public since 2020), root DB access for backdoor admin injection
- 1,342 configuration items encrypted via MySQL AES_ENCRYPT; extortion table README_RANSOM created
Default credentials and internet-exposed Nacos admin endpoints remain critical attack surface when chained with AI agent automation.
Related
- alibaba
- langflow
- jadepuffer
- agentic-threat-actors
- ai-agent-security
- supply-chain-security
- authentication-bypass