Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Gradio

Gradio Vendor Cyber Rating & Cyber Score

gradio.app

Generate an easy-to-use UI for your ML model, function, or API with only a few lines of code. Integrate directly into your Python notebook, or share a link with anyone. Gradio allows you to quickly create customizable UI components around your TensorFlow or PyTorch models, or even arbitrary Python functions. Mix and match components to support any combination of inputs and outputs. Our core library is free and open-source!


Gradio A.I CyberSecurity Scoring

Gradio
Company Information
Website:https://gradio.app
Employees number:5
Number of followers:74,297
NAICS:5112
Industry Type:Software Development
Homepage:gradio.app
Gradio Risk Score (AI oriented)
Between 700 and 749
logo
GradioSoftware Development
Updated:
19/07/2026
731/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Gradio Global Score (TPRM)
xxxx
logo
GradioSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Gradio
GradioModerate
Current Score
731Ba (MODERATE)
01000
1 incidents
-18 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
732Before Incident
AUGUST 2026
731Before Incident
JULY 2026
749Before Incident
Cyber Attack
19 Jul 2026Gradio
ComfyUI, Langflow, Ollama, Gradio and Open WebUI: NadMesh Uses Shodan to Find and Hijack Exposed AI and MCP Infrastructure

NadMesh Botnet Emerges as a Sophisticated Threat to AI and MCP Infrastructure

731After Incident
CRITICAL-18
GRACOMOLLOPELAN1784435194
NadMesh Botnet Emerges as a Sophisticated Threat to AI and MCP Infrastructure Security researchers at XLab have uncovered NadMesh, a Go-based botnet that has been rapidly spreading since early July 2026, marking a shift in cybercriminal tactics toward industrial-grade, ROI-driven attacks targeting Artificial Intelligence (AI) and Model Context Protocol (MCP) infrastructure. Unlike traditional worms, NadMesh operates as a closed-loop system dubbed the "n4d mesh controller" integrating autonomous scanning, over 20 unique exploitation vectors, and Shodan-powered intelligence harvesting. Its most distinctive feature is ai_harvest.py, a reconnaissance module that programmatically queries Shodan to identify exposed AI and automation services, including ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio. Discovered IP addresses are prioritized for immediate exploitation, allowing the botnet to bypass inefficient brute-force scanning. The botnet follows a five-stage operation: 1. Intelligence gathering (Shodan-driven targeting) 2. Centralized control (HMAC-authenticated beacons on ports 80 and 8443) 3. Autonomous task supply (dynamic payload delivery) 4. Polymorphic binary construction (Garble obfuscation + UPX compression) 5. Active delivery (persistence via SSH backdoors, cron watchdogs, and hidden binaries) NadMesh prioritizes AI service ports, including: - 8188 (ComfyUI) - 11434 (Ollama) - 5678 (n8n) - 7860 (Gradio) Its exploitation arsenal includes: - MCP JSON-RPC tool calls (command execution loops) - Kubernetes malicious pod creation (hostPath mount overrides) - Docker API container escapes (privileged container creation) - Unauthenticated Redis instances (CONFIG SET file writes) - Elasticsearch RCE, Jenkins Script Console, and WebLogic deserialization flaws Beyond initial access, NadMesh exfiltrates high-value data, including: - AWS access keys & Amazon Bedrock credentials - Kubernetes ServiceAccount tokens (cluster-admin scopes) - Docker configurations & locally hosted AI models (Llama2, Mistral, GPT-4 API tokens) - Internal MCP tool configurations (execute_sql, execute_shell) To evade detection, the malware employs automated honeypot avoidance, blacklisting IPs that fail infection attempts after 10 consecutive deployments. Its web-based management panel complete with conversion-funnel analytics and real-time operational visibility resembles enterprise-grade software, underscoring its sophistication. Indicators of Compromise (IOCs): - C2 IP Node: `209.99.186.235` - C2 CDN Domain: `cdnorigin.net`
INCIDENT DETAILS -
TYPE
Botnet
MOTIVATION
Data exfiltrationFinancial gainIndustrial-grade ROI-driven attacks
IMPACT
AWS access keysAmazon Bedrock credentialsKubernetes ServiceAccount tokens (cluster-admin scopes)Docker configurationsLocally hosted AI models (Llama2, Mistral, GPT-4 API tokens)Internal MCP tool configurations (execute_sql, execute_shell)AI and MCP infrastructureKubernetes clustersDocker containersRedis instancesElasticsearchJenkinsWebLogicOperational Impact: Potential disruption of AI and automation services due to exploitation and data exfiltration
DATA BREACH
CredentialsConfiguration filesAI model tokensServiceAccount tokensSensitivity Of Data: High
JUNE 2026
749Before Incident
MAY 2026
749Before Incident
APRIL 2026
749Before Incident
MARCH 2026
749Before Incident
FEBRUARY 2026
749Before Incident
JANUARY 2026
749Before Incident
DECEMBER 2025
749Before Incident
NOVEMBER 2025
749Before Incident
OCTOBER 2025
749Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Gradio ?
?
What was Gradio's A.I Rankiteo Cyber Score in August 2026 ?
?
What was Gradio's A.I Rankiteo Cyber Score in July 2026 ?
?
What was Gradio's A.I Rankiteo Cyber Score in June 2026 ?
?
What was Gradio's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Gradio's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Gradio's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Gradio's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Gradio's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Gradio's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Gradio's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Gradio's A.I Rankiteo Cyber Score in October 2025 ?
?
What is the average per-incident point impact on Gradio's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Gradio ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Gradio's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?