ComfyUI is a technology platform tracked by ThreatCluster, appearing in 3 threat clusters built from 4 intelligence report mentions.
ComfyUI is a technology platform tracked across 3 threat clusters and 4 intelligence report mentions on ThreatCluster. First observed April 8, 2026; most recent activity August 2, 2026.
A significant wave of cyberattacks has targeted ComfyUI servers, converting them into a botnet for cryptomining and proxy operations. Researchers from Censys reported that since March 12, 2026, over 1,000 publicly…
ComfyUI v0.23.0 has a critical remote code execution vulnerability (CVE-2026-68771) due to unsafe deserialization in the LoadTrainingDataset node. Unauthenticated remote attackers can exploit this flaw by uploading a…
UK small and medium-sized enterprises (SMEs) are increasingly vulnerable to sophisticated AI-driven scams, as highlighted by recent reports. The emergence of 'AI scams 2.0' combines traditional social engineering…
ComfyUI is a technology platform tracked by ThreatCluster, appearing in 3 threat clusters built from 4 intelligence report mentions.
The most recent intelligence report mentioning ComfyUI on ThreatCluster is dated August 2, 2026. Activity was first observed April 8, 2026, giving a tracked span from then to August 2, 2026.
Across ThreatCluster reporting, ComfyUI most frequently co-occurs with Botnet, Malware, Zero-day Exploit, Torch, Iran, among 12 tracked related entities.
The most significant recent cluster is “ComfyUI Servers Compromised for Cryptomining and Botnet Operations” (3 articles · Updated April 8, 2026). ComfyUI appears across 3 threat clusters in total, listed above with sources.
ComfyUI appears in 4 intelligence report mentions across 3 deduplicated threat clusters, aggregated from 17,000+ monitored sources.