Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
ComfyUI

ComfyUI Vendor Cyber Rating & Cyber Score

comfy.org

Comfy is the world's leading workflow engine for visual AI. Powered by ComfyUI, the open-source platform trusted by 4 million creators across 118,000+ GitHub stars and 60,000+ community-built nodes, Comfy gives creative and technical teams complete control over every model, every parameter, and every output. From independent artists to enterprise studios, professionals at Amazon Studios, Apple, Netflix, Nike, Ubisoft, and Pixomondo trust Comfy to power their AI-driven pipelines across VFX, animation, advertising, gaming, and eCommerce. Comfy's node-based canvas makes every AI decision visible, inspectable, and reproducible. No black boxes, no locked ecosystems. Whether you run workflows on your own hardware with Comfy Desktop, deploy at


ComfyUI A.I CyberSecurity Scoring

ComfyUI
Company Information
Website:https://comfy.org
Employees number:88
Number of followers:41,242
NAICS:5112
Industry Type:Software Development
Homepage:comfy.org
ComfyUI Risk Score (AI oriented)
Between 700 and 749
logo
ComfyUISoftware Development
Updated:
19/07/2026
734/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
ComfyUI Global Score (TPRM)
xxxx
logo
ComfyUISoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

ComfyUI
ComfyUIModerate
Current Score
734Ba (MODERATE)
01000
1 incidents
-18 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
735Before Incident
JULY 2026
752Before Incident
Cyber Attack
19 Jul 2026ComfyUI
ComfyUI, Langflow, Ollama, Gradio and Open WebUI: NadMesh Uses Shodan to Find and Hijack Exposed AI and MCP Infrastructure

NadMesh Botnet Emerges as a Sophisticated Threat to AI and MCP Infrastructure

734After Incident
CRITICAL-18
GRACOMOLLOPELAN1784435194
NadMesh Botnet Emerges as a Sophisticated Threat to AI and MCP Infrastructure Security researchers at XLab have uncovered NadMesh, a Go-based botnet that has been rapidly spreading since early July 2026, marking a shift in cybercriminal tactics toward industrial-grade, ROI-driven attacks targeting Artificial Intelligence (AI) and Model Context Protocol (MCP) infrastructure. Unlike traditional worms, NadMesh operates as a closed-loop system dubbed the "n4d mesh controller" integrating autonomous scanning, over 20 unique exploitation vectors, and Shodan-powered intelligence harvesting. Its most distinctive feature is ai_harvest.py, a reconnaissance module that programmatically queries Shodan to identify exposed AI and automation services, including ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio. Discovered IP addresses are prioritized for immediate exploitation, allowing the botnet to bypass inefficient brute-force scanning. The botnet follows a five-stage operation: 1. Intelligence gathering (Shodan-driven targeting) 2. Centralized control (HMAC-authenticated beacons on ports 80 and 8443) 3. Autonomous task supply (dynamic payload delivery) 4. Polymorphic binary construction (Garble obfuscation + UPX compression) 5. Active delivery (persistence via SSH backdoors, cron watchdogs, and hidden binaries) NadMesh prioritizes AI service ports, including: - 8188 (ComfyUI) - 11434 (Ollama) - 5678 (n8n) - 7860 (Gradio) Its exploitation arsenal includes: - MCP JSON-RPC tool calls (command execution loops) - Kubernetes malicious pod creation (hostPath mount overrides) - Docker API container escapes (privileged container creation) - Unauthenticated Redis instances (CONFIG SET file writes) - Elasticsearch RCE, Jenkins Script Console, and WebLogic deserialization flaws Beyond initial access, NadMesh exfiltrates high-value data, including: - AWS access keys & Amazon Bedrock credentials - Kubernetes ServiceAccount tokens (cluster-admin scopes) - Docker configurations & locally hosted AI models (Llama2, Mistral, GPT-4 API tokens) - Internal MCP tool configurations (execute_sql, execute_shell) To evade detection, the malware employs automated honeypot avoidance, blacklisting IPs that fail infection attempts after 10 consecutive deployments. Its web-based management panel complete with conversion-funnel analytics and real-time operational visibility resembles enterprise-grade software, underscoring its sophistication. Indicators of Compromise (IOCs): - C2 IP Node: `209.99.186.235` - C2 CDN Domain: `cdnorigin.net`
INCIDENT DETAILS -
TYPE
Botnet
MOTIVATION
Data exfiltrationFinancial gainIndustrial-grade ROI-driven attacks
IMPACT
AWS access keysAmazon Bedrock credentialsKubernetes ServiceAccount tokens (cluster-admin scopes)Docker configurationsLocally hosted AI models (Llama2, Mistral, GPT-4 API tokens)Internal MCP tool configurations (execute_sql, execute_shell)AI and MCP infrastructureKubernetes clustersDocker containersRedis instancesElasticsearchJenkinsWebLogicOperational Impact: Potential disruption of AI and automation services due to exploitation and data exfiltration
DATA BREACH
CredentialsConfiguration filesAI model tokensServiceAccount tokensSensitivity Of Data: High
JUNE 2026
752Before Incident
MAY 2026
752Before Incident
APRIL 2026
752Before Incident
MARCH 2026
752Before Incident
FEBRUARY 2026
752Before Incident
JANUARY 2026
752Before Incident
DECEMBER 2025
752Before Incident
NOVEMBER 2025
752Before Incident
OCTOBER 2025
752Before Incident
SEPTEMBER 2025
752Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for ComfyUI ?
?
What was ComfyUI's A.I Rankiteo Cyber Score in July 2026 ?
?
What was ComfyUI's A.I Rankiteo Cyber Score in June 2026 ?
?
What was ComfyUI's A.I Rankiteo Cyber Score in May 2026 ?
?
What was ComfyUI's A.I Rankiteo Cyber Score in April 2026 ?
?
What was ComfyUI's A.I Rankiteo Cyber Score in March 2026 ?
?
What was ComfyUI's A.I Rankiteo Cyber Score in February 2026 ?
?
What was ComfyUI's A.I Rankiteo Cyber Score in January 2026 ?
?
What was ComfyUI's A.I Rankiteo Cyber Score in December 2025 ?
?
What was ComfyUI's A.I Rankiteo Cyber Score in November 2025 ?
?
What was ComfyUI's A.I Rankiteo Cyber Score in October 2025 ?
?
What was ComfyUI's A.I Rankiteo Cyber Score in September 2025 ?
?
What is the average per-incident point impact on ComfyUI's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with ComfyUI ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view ComfyUI's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?