Threat reportThreat IntelligenceTL-2026-2113
Known Techniques, Unknown Speed: Aqua Security on How Frontier AI Collapses the Container Attack Chain
Known Techniques, Unknown Speed (TL-2026-2113), also tracked as Known Techniques Unknown Speed, is a high-severity tracked intrusion set, first published 2026-08-22. It is attributed to AI-augmented adversaries with low confidence, affects Industry-wide Containerized and Kubernetes-orchestrated workloads, maps to 12 MITRE ATT&CK techniques (T1046, T1059, T1071), and is covered by 9 detection rules and 12 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 12MITRE ATT&CK
- Actors
- 1AI-augmented adversaries
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 12Indicators of compromise
Key facts for TL-2026-2113
- Threat ID
- TL-2026-2113
- Also known as
- Known Techniques Unknown Speed, AI-Driven Container Attack Chain, Autonomous Runtime Collapse
- Severity
- HIGH
- Status
- ACTIVE
- Category
- THREAT_INTEL
- First published
- Last reviewed
- Attribution
- AI-augmented adversaries
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- technology, cloud service providers, financial services, cryptocurrency exchanges, critical infrastructure, government administration
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 12
Malware and tooling in Known Techniques, Unknown Speed
Malware and tooling: TeamPCP, VoidLink, Anthropic Claude 'Mythos' (frontier vulnerability-research model), Peirates - S0683, curl, wget
How Known Techniques, Unknown Speed works
Aqua Security argues frontier AI models execute known container/cloud-native attack chains end-to-end without human direction at a speed that eliminates the discovery-to-exploitation window, citing Anthropic's Mythos model finding 271 previously unknown Firefox vulnerabilities as illustrative evidence. Aqua outlines a six-stage AI-driven attack pattern against containerized environments and argues simultaneous runtime enforcement across every stage is the required defense.
This is a TREND / threat-landscape item, not a single-CVE threat. Aqua Security (author: Erin Stephan, Head of Product Marketing; published May 7, 2026, category 'Autonomous Runtime Security') argues in 'Known Techniques, Unknown Speed: How AI Changes the Attack Chain' that frontier AI models introduce no fundamentally novel attack techniques against containerized/cloud-native environments, but instead execute the same well-documented technique chains end-to-end, autonomously, and at a speed that collapses the traditional discovery-to-exploitation window that defenders rely on for triage and patching.
Aqua's central evidence point is real and independently corroborated: Anthropic's 'Mythos' model (a Claude-family frontier vulnerability-research system, unveiled April 2026) was used by Mozilla to analyze Firefox and surfaced 271 previously unknown vulnerabilities, which shipped fixed in Firefox 150 on April 22, 2026. Three received public CVE credit to the model (CVE-2026-6746, CVE-2026-6757, CVE-2026-6758); most of the 271 were defense-in-depth issues, hardening flaws, or bugs in non-exploitable code paths that did not individually meet the bar for a CVE. Firefox CTO Bobby Holley characterized the result as significant in scale but not in kind: 'we also haven't seen any bugs that couldn't have been found by an elite human researcher,' rejecting the idea that Mythos found 'entirely new forms of vulnerabilities.' Aqua's blog frames the same result as '271 previously unknown exploit vectors in Firefox in under 72 hours' against a Mozilla estimate of four to seven months of manual red-teaming for equivalent coverage; neither SecurityWeek's nor TechCrunch's independent reporting on the disclosure specifies an exact discovery timeframe, so the 72-hour figure should be read as Aqua's own framing of the finding rather than an independently confirmed measurement. SecurityWeek separately reports Palo Alto Networks testing showing Mythos achieving 'the equivalent of a year's worth of pentesting in under three weeks' on general assessments (not Firefox-specific).
Aqua's illustrative six-stage AI-driven container attack chain: (1) Reconnaissance/Resource Development — kernel-version enumeration, mounted-volume probing, and cluster metadata-endpoint querying, plus parallel port scanning (5+ privileged and 10+ ephemeral ports within 5 minutes); (2) Delivery/Initial Access — exploitation of a sidecar container logic flaw, including novel vulnerability analysis that does not require a known CVE; (3) Execution/Persistence — reverse-shell spawning, LD_PRELOAD shared-library injection into an existing privileged host process before namespace isolation completes, and fileless payload deployment into writable-executable memory; (4) Command and Control — outbound TLS connections to attacker infrastructure using standard pre-installed tools (curl, wget) for staging and persistence; (5) Lateral Movement/Privilege Escalation — kernel-primitive exploitation for container breakout combined with theft and reuse of the Kubernetes service-account token mounted inside the container to authenticate to the API server; (6) Impact — cryptominer deployment, data exfiltration from mounted secrets volumes, and ransomware distribution across persistent volumes. Aqua names no specific CVE, malware sample, or threat actor for this chain — it is presented generically — and argues that because an autonomous agent moves through all six stages without pausing for human decision points, only runtime enforcement operating simultaneously at every stage (not point-in-time scanning or patch-velocity programs) can interrupt it before impact.
Every individual technique in Aqua's generic chain has a documented real-world precedent that grounds the analysis: Unit 42 (Palo Alto Networks) reports Kubernetes service-account-token theft increased 282% year-over-year and was observed in 22% of cloud environments in 2025, with tokens mounted by default at /var/run/secrets/kubernetes.io/serviceaccount/token; malware frameworks TeamPCP and VoidLink now ship dedicated Kubernetes credential-harvesting modules; the Go-based post-exploitation tool Peirates (MITRE ATT&CK software S0683), used by the cloud-focused intrusion sets SCARLETEEL and TeamTNT, automates namespace/role enumeration, secret theft, cloud API misuse, and node attacks. Unit 42 also documents a mid-2025 cryptocurrency-exchange compromise attributed to Slow Pisces (Lazarus/TraderTraitor) that followed spearphishing → malicious pod deployment → service-account-token extraction → API enumeration → cloud-infrastructure compromise, and a distinct initial-access precedent for 'sidecar/application logic flaw' exploitation: CVE-2025-55182 ('React2Shell'), a CVSS 10.0 pre-authentication remote-code-execution vulnerability in React Server Components (react-server-dom-webpack/turbopack/parcel 19.0.0-19.2.0; Next.js 15.0.0-16.0.7) disclosed December 3, 2025 and observed under active exploitation against containerized application backends within two days, with attackers enumerating cluster resources and harvesting mounted service-account tokens post-exploitation — the exact recon-then-token-theft pattern Aqua's chain describes.
Aqua's prescriptive thesis is runtime enforcement that operates at every stage of the chain simultaneously, blocking a process from advancing to the next stage the moment it deviates from policy, rather than relying on triage workflows (SIEM alert → tier-1 pickup → ticket → patch) whose latency assumes a human-speed attacker.
MITRE ATT&CK techniques used in TL-2026-2113
Discovery
T1046 Network Service Discovery; T1613 Container and Resource Discovery
Execution
T1059 Command and Scripting Interpreter
Command and Control
T1071 Application Layer Protocol
Privilege Escalation
T1078 Valid Accounts; T1611 Escape to Host
Initial Access
T1190 Exploit Public-Facing Application
Impact
Credential Access
T1528 Steal Application Access Token; T1552 Unsecured Credentials
stealth
Reconnaissance
Affected products and versions in Known Techniques, Unknown Speed
- Industry-wide — Containerized and Kubernetes-orchestrated workloads
Vulnerable versions: environments lacking runtime enforcement across every attack stage
Fixed in: environments enforcing continuous runtime policy from reconnaissance through impact - Mozilla — Firefox (illustrative Mythos exploit-discovery target)
Vulnerable versions: Firefox builds prior to 150
Fixed in: Firefox 150 (April 22, 2026) - Meta / Vercel — React Server Components / Next.js (CVE-2025-55182 'React2Shell', cited container initial-access precedent)
Vulnerable versions: react-server-dom-webpack/turbopack/parcel 19.0.0-19.2.0; Next.js 15.0.0-16.0.7 and specific canary builds
Fixed in: patched releases per vendor advisory, December 2025
Remediation for Known Techniques, Unknown Speed
Patches
- Patch container-adjacent pre-auth RCE vectors on an emergency cadence — CVE-2025-55182 (React2Shell) was under active exploitation within two days of disclosure
- Track vendor advisories for vulnerability classes disclosed at AI-assisted speed (e.g., Firefox 150 / CVE-2026-6746, CVE-2026-6757, CVE-2026-6758) and prioritize triage accordingly
Immediate actions
- Enforce runtime policy simultaneously at every stage of the container lifecycle (reconnaissance through impact) rather than relying on point-in-time scanning, per Aqua's simultaneous-enforcement model
- Disable automatic service-account token mounting (automountServiceAccountToken: false) on workloads that do not require Kubernetes API server access
- Apply seccomp/AppArmor/SELinux profiles that block LD_PRELOAD environment-variable injection and dynamic-linker hijacking in running containers
Workarounds
- Restrict node-level kernel-primitive access (seccomp default profile, drop unneeded Linux capabilities) to reduce container-breakout surface
- Segment Kubernetes clusters/namespaces so a single sidecar compromise cannot reach cluster-wide metadata endpoints or cloud credentials
Longer-term hardening
- Adopt bound, time-limited, audience-restricted Kubernetes service-account tokens via the TokenRequest API instead of long-lived tokens mounted at /var/run/secrets/kubernetes.io/serviceaccount/token
- Deploy runtime detection for anomalous outbound TLS connections and curl/wget invocations originating from workload containers (LOLBin-style C2 staging)
- Enforce least-privilege RBAC on service accounts to limit blast radius if a token is stolen, per Unit 42's Slow Pisces cryptocurrency-exchange case study
- Harden sidecar-container trust boundaries and validate inter-container logic paths that can bypass namespace isolation checks
Timeline of Known Techniques, Unknown Speed
- Unit 42 documents a cryptocurrency-exchange compromise (approximate mid-2025 timing) attributed to Slow Pisces (Lazarus/TraderTraitor): spearphishing, malicious pod deployment, Kubernetes service-account-token theft, API enumeration, and cloud-infrastructure compromise.
- CVE-2025-55182 ('React2Shell'), a CVSS 10.0 pre-authentication RCE in React Server Components, is disclosed — the container-application initial-access precedent later echoed in Aqua's generic sidecar-exploitation stage.
- Unit 42 observes active exploitation of CVE-2025-55182 against containerized application backends within two days of disclosure, with attackers enumerating cluster resources and harvesting mounted Kubernetes service-account tokens post-exploitation.
- Palo Alto Networks testing, reported by SecurityWeek, shows Anthropic's Mythos model achieving 'the equivalent of a year's worth of pentesting in under three weeks' on general assessments.
- Slashdot reports Mozilla used Anthropic's Mythos model to find and fix 271 bugs in Firefox.
- Mozilla ships Firefox 150, patching all 271 vulnerabilities Mythos identified; three receive public CVE credit (CVE-2026-6746, CVE-2026-6757, CVE-2026-6758). Firefox CTO Bobby Holley states none of the bugs 'couldn't have been found by an elite human researcher.'
- TechCrunch publishes a feature on Mythos as an agentic vulnerability-research system that assesses and filters its own findings, including sandbox-escape bugs requiring multi-step exploit construction, and reports Firefox shipped 423 bug fixes in April 2026 versus 31 the prior year.
- Aqua Security (Erin Stephan) publishes 'Known Techniques, Unknown Speed: How AI Changes the Attack Chain,' citing the Mythos/Firefox result ('271 previously unknown exploit vectors in under 72 hours' vs. a 4-7 month manual-red-team estimate) as evidence for a six-stage AI-driven container attack chain and a simultaneous-runtime-enforcement defense thesis.
Sources cited for Known Techniques, Unknown Speed
- Known Techniques, Unknown Speed: How AI Changes the Attack Chain
- Claude Mythos Finds 271 Firefox Vulnerabilities
- Mythos found 271 Firefox flaws – none a human couldn't spot
- How Anthropic's Mythos has rewritten Firefox's approach to cybersecurity
- Mozilla Uses Anthropic's Mythos To Fix 271 Bugs In Firefox
- Anthropic Mythos finds 271 Firefox vulnerabilities
- Understanding Current Threats to Kubernetes Environments
- NVD - CVE-2025-55182 Detail
Detection coverage for TL-2026-2113
As of 2026-08-22, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2113 across Splunk SPL, Microsoft KQL and Sigma, covering 12 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.