Threat reportThreat IntelligenceTL-2026-2113

Known Techniques, Unknown Speed: Aqua Security on How Frontier AI Collapses the Container Attack Chain

highACTIVE

Known Techniques, Unknown Speed (TL-2026-2113), also tracked as Known Techniques Unknown Speed, is a high-severity tracked intrusion set, first published 2026-08-22. It is attributed to AI-augmented adversaries with low confidence, affects Industry-wide Containerized and Kubernetes-orchestrated workloads, maps to 12 MITRE ATT&CK techniques (T1046, T1059, T1071), and is covered by 9 detection rules and 12 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
12MITRE ATT&CK
Actors
1AI-augmented adversaries
Detection rules
9SPL · KQL · Sigma
IOCs
12Indicators of compromise

Key facts for TL-2026-2113

Threat ID
TL-2026-2113
Also known as
Known Techniques Unknown Speed, AI-Driven Container Attack Chain, Autonomous Runtime Collapse
Severity
HIGH
Status
ACTIVE
Category
THREAT_INTEL
First published
Last reviewed
Attribution
AI-augmented adversaries
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
technology, cloud service providers, financial services, cryptocurrency exchanges, critical infrastructure, government administration
Target regions
Global
Detection rules
9
Indicators of compromise
12

Malware and tooling in Known Techniques, Unknown Speed

Malware and tooling: TeamPCP, VoidLink, Anthropic Claude 'Mythos' (frontier vulnerability-research model), Peirates - S0683, curl, wget

How Known Techniques, Unknown Speed works

Aqua Security argues frontier AI models execute known container/cloud-native attack chains end-to-end without human direction at a speed that eliminates the discovery-to-exploitation window, citing Anthropic's Mythos model finding 271 previously unknown Firefox vulnerabilities as illustrative evidence. Aqua outlines a six-stage AI-driven attack pattern against containerized environments and argues simultaneous runtime enforcement across every stage is the required defense.

This is a TREND / threat-landscape item, not a single-CVE threat. Aqua Security (author: Erin Stephan, Head of Product Marketing; published May 7, 2026, category 'Autonomous Runtime Security') argues in 'Known Techniques, Unknown Speed: How AI Changes the Attack Chain' that frontier AI models introduce no fundamentally novel attack techniques against containerized/cloud-native environments, but instead execute the same well-documented technique chains end-to-end, autonomously, and at a speed that collapses the traditional discovery-to-exploitation window that defenders rely on for triage and patching.

Aqua's central evidence point is real and independently corroborated: Anthropic's 'Mythos' model (a Claude-family frontier vulnerability-research system, unveiled April 2026) was used by Mozilla to analyze Firefox and surfaced 271 previously unknown vulnerabilities, which shipped fixed in Firefox 150 on April 22, 2026. Three received public CVE credit to the model (CVE-2026-6746, CVE-2026-6757, CVE-2026-6758); most of the 271 were defense-in-depth issues, hardening flaws, or bugs in non-exploitable code paths that did not individually meet the bar for a CVE. Firefox CTO Bobby Holley characterized the result as significant in scale but not in kind: 'we also haven't seen any bugs that couldn't have been found by an elite human researcher,' rejecting the idea that Mythos found 'entirely new forms of vulnerabilities.' Aqua's blog frames the same result as '271 previously unknown exploit vectors in Firefox in under 72 hours' against a Mozilla estimate of four to seven months of manual red-teaming for equivalent coverage; neither SecurityWeek's nor TechCrunch's independent reporting on the disclosure specifies an exact discovery timeframe, so the 72-hour figure should be read as Aqua's own framing of the finding rather than an independently confirmed measurement. SecurityWeek separately reports Palo Alto Networks testing showing Mythos achieving 'the equivalent of a year's worth of pentesting in under three weeks' on general assessments (not Firefox-specific).

Aqua's illustrative six-stage AI-driven container attack chain: (1) Reconnaissance/Resource Development — kernel-version enumeration, mounted-volume probing, and cluster metadata-endpoint querying, plus parallel port scanning (5+ privileged and 10+ ephemeral ports within 5 minutes); (2) Delivery/Initial Access — exploitation of a sidecar container logic flaw, including novel vulnerability analysis that does not require a known CVE; (3) Execution/Persistence — reverse-shell spawning, LD_PRELOAD shared-library injection into an existing privileged host process before namespace isolation completes, and fileless payload deployment into writable-executable memory; (4) Command and Control — outbound TLS connections to attacker infrastructure using standard pre-installed tools (curl, wget) for staging and persistence; (5) Lateral Movement/Privilege Escalation — kernel-primitive exploitation for container breakout combined with theft and reuse of the Kubernetes service-account token mounted inside the container to authenticate to the API server; (6) Impact — cryptominer deployment, data exfiltration from mounted secrets volumes, and ransomware distribution across persistent volumes. Aqua names no specific CVE, malware sample, or threat actor for this chain — it is presented generically — and argues that because an autonomous agent moves through all six stages without pausing for human decision points, only runtime enforcement operating simultaneously at every stage (not point-in-time scanning or patch-velocity programs) can interrupt it before impact.

Every individual technique in Aqua's generic chain has a documented real-world precedent that grounds the analysis: Unit 42 (Palo Alto Networks) reports Kubernetes service-account-token theft increased 282% year-over-year and was observed in 22% of cloud environments in 2025, with tokens mounted by default at /var/run/secrets/kubernetes.io/serviceaccount/token; malware frameworks TeamPCP and VoidLink now ship dedicated Kubernetes credential-harvesting modules; the Go-based post-exploitation tool Peirates (MITRE ATT&CK software S0683), used by the cloud-focused intrusion sets SCARLETEEL and TeamTNT, automates namespace/role enumeration, secret theft, cloud API misuse, and node attacks. Unit 42 also documents a mid-2025 cryptocurrency-exchange compromise attributed to Slow Pisces (Lazarus/TraderTraitor) that followed spearphishing → malicious pod deployment → service-account-token extraction → API enumeration → cloud-infrastructure compromise, and a distinct initial-access precedent for 'sidecar/application logic flaw' exploitation: CVE-2025-55182 ('React2Shell'), a CVSS 10.0 pre-authentication remote-code-execution vulnerability in React Server Components (react-server-dom-webpack/turbopack/parcel 19.0.0-19.2.0; Next.js 15.0.0-16.0.7) disclosed December 3, 2025 and observed under active exploitation against containerized application backends within two days, with attackers enumerating cluster resources and harvesting mounted service-account tokens post-exploitation — the exact recon-then-token-theft pattern Aqua's chain describes.

Aqua's prescriptive thesis is runtime enforcement that operates at every stage of the chain simultaneously, blocking a process from advancing to the next stage the moment it deviates from policy, rather than relying on triage workflows (SIEM alert → tier-1 pickup → ticket → patch) whose latency assumes a human-speed attacker.

MITRE ATT&CK techniques used in TL-2026-2113

Discovery

T1046 Network Service Discovery; T1613 Container and Resource Discovery

Execution

T1059 Command and Scripting Interpreter

Command and Control

T1071 Application Layer Protocol

Privilege Escalation

T1078 Valid Accounts; T1611 Escape to Host

Initial Access

T1190 Exploit Public-Facing Application

Impact

T1496 Resource Hijacking

Credential Access

T1528 Steal Application Access Token; T1552 Unsecured Credentials

stealth

T1574 Hijack Execution Flow

Reconnaissance

T1595 Active Scanning

Affected products and versions in Known Techniques, Unknown Speed

  • Industry-wide — Containerized and Kubernetes-orchestrated workloads
    Vulnerable versions: environments lacking runtime enforcement across every attack stage
    Fixed in: environments enforcing continuous runtime policy from reconnaissance through impact
  • Mozilla — Firefox (illustrative Mythos exploit-discovery target)
    Vulnerable versions: Firefox builds prior to 150
    Fixed in: Firefox 150 (April 22, 2026)
  • Meta / Vercel — React Server Components / Next.js (CVE-2025-55182 'React2Shell', cited container initial-access precedent)
    Vulnerable versions: react-server-dom-webpack/turbopack/parcel 19.0.0-19.2.0; Next.js 15.0.0-16.0.7 and specific canary builds
    Fixed in: patched releases per vendor advisory, December 2025

Remediation for Known Techniques, Unknown Speed

Patches

  • Patch container-adjacent pre-auth RCE vectors on an emergency cadence — CVE-2025-55182 (React2Shell) was under active exploitation within two days of disclosure
  • Track vendor advisories for vulnerability classes disclosed at AI-assisted speed (e.g., Firefox 150 / CVE-2026-6746, CVE-2026-6757, CVE-2026-6758) and prioritize triage accordingly

Immediate actions

  • Enforce runtime policy simultaneously at every stage of the container lifecycle (reconnaissance through impact) rather than relying on point-in-time scanning, per Aqua's simultaneous-enforcement model
  • Disable automatic service-account token mounting (automountServiceAccountToken: false) on workloads that do not require Kubernetes API server access
  • Apply seccomp/AppArmor/SELinux profiles that block LD_PRELOAD environment-variable injection and dynamic-linker hijacking in running containers

Workarounds

  • Restrict node-level kernel-primitive access (seccomp default profile, drop unneeded Linux capabilities) to reduce container-breakout surface
  • Segment Kubernetes clusters/namespaces so a single sidecar compromise cannot reach cluster-wide metadata endpoints or cloud credentials

Longer-term hardening

  • Adopt bound, time-limited, audience-restricted Kubernetes service-account tokens via the TokenRequest API instead of long-lived tokens mounted at /var/run/secrets/kubernetes.io/serviceaccount/token
  • Deploy runtime detection for anomalous outbound TLS connections and curl/wget invocations originating from workload containers (LOLBin-style C2 staging)
  • Enforce least-privilege RBAC on service accounts to limit blast radius if a token is stolen, per Unit 42's Slow Pisces cryptocurrency-exchange case study
  • Harden sidecar-container trust boundaries and validate inter-container logic paths that can bypass namespace isolation checks

Timeline of Known Techniques, Unknown Speed

  • Unit 42 documents a cryptocurrency-exchange compromise (approximate mid-2025 timing) attributed to Slow Pisces (Lazarus/TraderTraitor): spearphishing, malicious pod deployment, Kubernetes service-account-token theft, API enumeration, and cloud-infrastructure compromise.
  • CVE-2025-55182 ('React2Shell'), a CVSS 10.0 pre-authentication RCE in React Server Components, is disclosed — the container-application initial-access precedent later echoed in Aqua's generic sidecar-exploitation stage.
  • Unit 42 observes active exploitation of CVE-2025-55182 against containerized application backends within two days of disclosure, with attackers enumerating cluster resources and harvesting mounted Kubernetes service-account tokens post-exploitation.
  • Palo Alto Networks testing, reported by SecurityWeek, shows Anthropic's Mythos model achieving 'the equivalent of a year's worth of pentesting in under three weeks' on general assessments.
  • Slashdot reports Mozilla used Anthropic's Mythos model to find and fix 271 bugs in Firefox.
  • Mozilla ships Firefox 150, patching all 271 vulnerabilities Mythos identified; three receive public CVE credit (CVE-2026-6746, CVE-2026-6757, CVE-2026-6758). Firefox CTO Bobby Holley states none of the bugs 'couldn't have been found by an elite human researcher.'
  • TechCrunch publishes a feature on Mythos as an agentic vulnerability-research system that assesses and filters its own findings, including sandbox-escape bugs requiring multi-step exploit construction, and reports Firefox shipped 423 bug fixes in April 2026 versus 31 the prior year.
  • Aqua Security (Erin Stephan) publishes 'Known Techniques, Unknown Speed: How AI Changes the Attack Chain,' citing the Mythos/Firefox result ('271 previously unknown exploit vectors in under 72 hours' vs. a 4-7 month manual-red-team estimate) as evidence for a six-stage AI-driven container attack chain and a simultaneous-runtime-enforcement defense thesis.

Sources cited for Known Techniques, Unknown Speed

Detection coverage for TL-2026-2113

As of 2026-08-22, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2113 across Splunk SPL, Microsoft KQL and Sigma, covering 12 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
12 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats