{
  "Event": {
    "analysis": "1",
    "date": "2026-06-15",
    "extends_uuid": "",
    "info": "[Threat Intel] How attackers are jailbreaking LLMs with CTF framing and how to catch them",
    "protected": false,
    "publish_timestamp": "1782352596",
    "published": true,
    "threat_level_id": "3",
    "timestamp": "1782352596",
    "uuid": "a667f34d-d768-47b3-9f64-ae7a72b86b82",
    "Orgc": {
      "name": "Rectifyq",
      "uuid": "cd9bd516-61fa-476b-980f-2f8de03992d4"
    },
    "Tag": [
      {
        "colour": "#ffffff",
        "local": false,
        "name": "tlp:clear",
        "relationship_type": ""
      },
      {
        "colour": "#004646",
        "local": false,
        "name": "type:OSINT",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"none-from-src\"",
        "relationship_type": ""
      },
      {
        "colour": "#b94b1d",
        "local": false,
        "name": "rectifyq:mitre-att&ck=\"from-OTX\"",
        "relationship_type": ""
      },
      {
        "colour": "#49a260",
        "local": false,
        "name": "rectifyq:category=\"threat\"",
        "relationship_type": ""
      },
      {
        "colour": "#130049",
        "local": false,
        "name": "rectifyq:sub-category=\"campaign-analysis\"",
        "relationship_type": ""
      },
      {
        "colour": "#18005c",
        "local": false,
        "name": "rectifyq:topic=\"ai\"",
        "relationship_type": ""
      },
      {
        "colour": "#ffd12e",
        "local": false,
        "name": "rectifyq:target=\"broad-based\"",
        "relationship_type": ""
      },
      {
        "colour": "#55acee",
        "local": false,
        "name": "rectifyq:MY-relevancy=\"potentially-relevant\"",
        "relationship_type": ""
      },
      {
        "colour": "#626567",
        "local": false,
        "name": "rectifyq:no-samples-in=\"MalwareBazaar\"",
        "relationship_type": ""
      },
      {
        "colour": "#626567",
        "local": false,
        "name": "rectifyq:no-samples-in=\"Tria.ge\"",
        "relationship_type": ""
      },
      {
        "colour": "#3800d9",
        "local": false,
        "name": "rectifyq:action-taken=\"VT-comment\"",
        "relationship_type": ""
      },
      {
        "colour": "#3d00e9",
        "local": false,
        "name": "rectifyq:action-taken=\"telegram\"",
        "relationship_type": ""
      }
    ],
    "Attribute": [
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1781665222",
        "to_ids": false,
        "type": "link",
        "uuid": "54c36595-68ec-408b-8829-c43f9c8c29d6",
        "value": "https://www.sysdig.com/blog/how-attackers-are-jailbreaking-llms-with-ctf-framing-and-how-to-catch-them",
        "Tag": [
          {
            "colour": "#6b003a",
            "local": true,
            "name": "workflow:todo=\"create-missing-misp-galaxy-cluster\"",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Other",
        "comment": "Description",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1781665222",
        "to_ids": false,
        "type": "text",
        "uuid": "af564a9a-2e8d-4b2d-95d3-b18695b61d77",
        "value": "Threat actors are bypassing AI model safety guardrails by framing exploit requests as legitimate security research, such as capture-the-flag challenges or CVE-hunting exercises. This technique manipulates upstream LLMs into generating working exploit code that attackers deploy against real targets. Multiple independent operators have been observed targeting five applications\u2014PraisonAI, LiteLLM, FastGPT, Open-WebUI, and Gotenberg\u2014using CVE-templated User-Agent strings and similar framing across multiple fields including passwords and AWS session names. The jailbreak framing leaks into every LLM-generated field because the model incorporates the prompt context into its output. This pattern represents a shift from manually written scanners to LLM-assisted exploit generation, creating detectable fingerprints across request headers, account aliases, and IAM session names that legitimate traffic rarely exhibits."
      },
      {
        "category": "Other",
        "comment": "Summary",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1781665222",
        "to_ids": false,
        "type": "text",
        "uuid": "c10bdff1-96be-473c-8bff-366670f1cd13",
        "value": "Name: How attackers are jailbreaking LLMs with CTF framing and how to catch them\nAuthor: AlienVault\nAdversary: \nTags: [\"cve-2026-39987\", \"cve-2026-45397\", \"cve-2026-42271\", \"cve-2026-42302\", \"cve exploitation\", \"cve-2026-42266\", \"cve-2026-45301\", \"cve-2026-42208\", \"llm jailbreaking\", \"ai platform targeting\", \"cve-2026-42589\", \"cve-2026-44694\", \"cve-2026-33017\", \"cve-2026-45672\", \"cve-2026-45331\", \"cve-2026-44336\", \"prompt injection\", \"cve-2026-40281\", \"cve-2026-47391\", \"credential harvesting\", \"rce campaigns\", \"ai agent exploitation\", \"ctf framing\"]\nTgtd countries: []\nMlwr families: []\nAttack_ids: []\nIndustries: []"
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1782346149",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "76b82cdd-f2a3-44fc-913a-79b84a504a5c",
        "value": "103.142.140.238",
        "Tag": [
          {
            "colour": "#bb0b81",
            "local": false,
            "name": "asn:asn=\"41378\"",
            "relationship_type": ""
          },
          {
            "colour": "#a230b9",
            "local": false,
            "name": "asn:as-owner=\"KIRINONET\"",
            "relationship_type": ""
          },
          {
            "colour": "#d16c37",
            "local": false,
            "name": "asn:as-country=\"US\"",
            "relationship_type": ""
          },
          {
            "colour": "#0088cc",
            "local": false,
            "name": "misp-galaxy:country=\"united states of america\"",
            "relationship_type": ""
          },
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1781665222",
        "to_ids": false,
        "type": "vulnerability",
        "uuid": "a1c53b10-e877-46d7-9b5a-7f8500ca092e",
        "value": "CVE-2026-0770"
      },
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1781665222",
        "to_ids": false,
        "type": "vulnerability",
        "uuid": "2ce3360b-877b-45d8-a5f7-83e1644488f8",
        "value": "CVE-2026-33017"
      },
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1781665222",
        "to_ids": false,
        "type": "vulnerability",
        "uuid": "ee5adc79-79dc-4f9b-b524-2ac4eff88901",
        "value": "CVE-2026-39987"
      },
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1781665222",
        "to_ids": false,
        "type": "vulnerability",
        "uuid": "7d20ceb9-6852-42ab-a6dd-4cbc40511e4d",
        "value": "CVE-2026-42208"
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1782346170",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "d643c078-9464-417f-b0a0-76cc6c202926",
        "value": "212.107.30.69",
        "Tag": [
          {
            "colour": "#bb0b81",
            "local": false,
            "name": "asn:asn=\"41378\"",
            "relationship_type": ""
          },
          {
            "colour": "#a230b9",
            "local": false,
            "name": "asn:as-owner=\"KIRINONET\"",
            "relationship_type": ""
          },
          {
            "colour": "#d16c37",
            "local": false,
            "name": "asn:as-country=\"US\"",
            "relationship_type": ""
          },
          {
            "colour": "#0088cc",
            "local": false,
            "name": "misp-galaxy:country=\"united states of america\"",
            "relationship_type": ""
          },
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1781665222",
        "to_ids": false,
        "type": "vulnerability",
        "uuid": "70b8039d-99f8-4f18-baca-8523ac213318",
        "value": "CVE-2026-40281"
      },
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1781665222",
        "to_ids": false,
        "type": "vulnerability",
        "uuid": "ab10c2cd-f7a9-4d9a-9958-e4ca0468ff35",
        "value": "CVE-2026-42271"
      },
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1781665222",
        "to_ids": false,
        "type": "vulnerability",
        "uuid": "ca15d6cf-36de-41bd-848b-605232e3d85c",
        "value": "CVE-2026-44336"
      },
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1781665222",
        "to_ids": false,
        "type": "vulnerability",
        "uuid": "8306219f-e1c1-4352-832f-4321f77f619f",
        "value": "CVE-2026-44694"
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1782346191",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "bce0dd53-d971-4c4d-a432-66778ed6f54e",
        "value": "115.171.80.253",
        "Tag": [
          {
            "colour": "#b2d1cd",
            "local": false,
            "name": "asn:asn=\"4847\"",
            "relationship_type": ""
          },
          {
            "colour": "#0a7ba8",
            "local": false,
            "name": "asn:as-owner=\"CNIX-AP China Networks Inter-Exchange\"",
            "relationship_type": ""
          },
          {
            "colour": "#9256df",
            "local": false,
            "name": "asn:as-country=\"CN\"",
            "relationship_type": ""
          },
          {
            "colour": "#0088cc",
            "local": false,
            "name": "misp-galaxy:country=\"china\"",
            "relationship_type": ""
          },
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1781665222",
        "to_ids": false,
        "type": "vulnerability",
        "uuid": "a4ffc704-66fd-479f-a4b9-3e6eea011ea3",
        "value": "CVE-2026-42589"
      },
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1781665222",
        "to_ids": false,
        "type": "vulnerability",
        "uuid": "f08185ab-e4f4-40ce-a41b-42ca7ab1de09",
        "value": "CVE-2026-45331"
      },
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1781665222",
        "to_ids": false,
        "type": "vulnerability",
        "uuid": "82a3f104-d611-4b24-ad71-0bd3bdb0e85a",
        "value": "CVE-2026-45672"
      },
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1781665222",
        "to_ids": false,
        "type": "vulnerability",
        "uuid": "f7f07d0a-d974-40f5-9bec-6cb0ac9f8b33",
        "value": "CVE-2026-45301"
      },
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1781665222",
        "to_ids": false,
        "type": "vulnerability",
        "uuid": "1f5fdd5c-f383-4649-83f4-fe599df8d318",
        "value": "CVE-2026-47391"
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1782346212",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "41f4b2dd-ee2e-4450-aa80-2badf58e8450",
        "value": "103.142.140.246",
        "Tag": [
          {
            "colour": "#bb0b81",
            "local": false,
            "name": "asn:asn=\"41378\"",
            "relationship_type": ""
          },
          {
            "colour": "#a230b9",
            "local": false,
            "name": "asn:as-owner=\"KIRINONET\"",
            "relationship_type": ""
          },
          {
            "colour": "#d16c37",
            "local": false,
            "name": "asn:as-country=\"US\"",
            "relationship_type": ""
          },
          {
            "colour": "#0088cc",
            "local": false,
            "name": "misp-galaxy:country=\"united states of america\"",
            "relationship_type": ""
          },
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1782346233",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "f25600f0-423c-4fc6-ad9f-581999186c18",
        "value": "38.181.81.164",
        "Tag": [
          {
            "colour": "#5a0d99",
            "local": false,
            "name": "asn:asn=\"398704\"",
            "relationship_type": ""
          },
          {
            "colour": "#dee939",
            "local": false,
            "name": "asn:as-owner=\"STACKSINC-BACKBONE\"",
            "relationship_type": ""
          },
          {
            "colour": "#d16c37",
            "local": false,
            "name": "asn:as-country=\"US\"",
            "relationship_type": ""
          },
          {
            "colour": "#0088cc",
            "local": false,
            "name": "misp-galaxy:country=\"united states of america\"",
            "relationship_type": ""
          },
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      },
      {
        "category": "Network activity",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1782346254",
        "to_ids": true,
        "type": "ip-dst",
        "uuid": "dd4173de-ccc7-4109-853d-d4c1c60f6134",
        "value": "68.77.201.89",
        "Tag": [
          {
            "colour": "#6dc194",
            "local": false,
            "name": "asn:asn=\"7018\"",
            "relationship_type": ""
          },
          {
            "colour": "#f71a75",
            "local": false,
            "name": "asn:as-owner=\"ATT-INTERNET4\"",
            "relationship_type": ""
          },
          {
            "colour": "#d16c37",
            "local": false,
            "name": "asn:as-country=\"US\"",
            "relationship_type": ""
          },
          {
            "colour": "#0088cc",
            "local": false,
            "name": "misp-galaxy:country=\"united states of america\"",
            "relationship_type": ""
          },
          {
            "colour": "#342294",
            "local": false,
            "name": "CommentAdded",
            "relationship_type": ""
          }
        ]
      }
    ]
  }
}