Real-time status of NovaMind AI services and infrastructure.
All NovaMind services are running normally.
/.env, /.git/HEAD, /api/v1/admin, and /api/v1/training-data.
Every request included a spoofed X-Forwarded-For header, triggering Cloudflare's
Drupal CVE-2018-14774 managed rule on all traffic. SQLi payloads were injected into API query parameters.
requests library
JA4 hash does not change regardless of what User-Agent is set. Cloudflare Bot Management
identified all traffic as the same origin.
/api/v1/chat endpoint, sending 16+ prompt injection payloads:
DAN jailbreaks ("Ignore all previous instructions…"), system prompt extraction attempts,
training data exfiltration requests, and Log4Shell JNDI callbacks embedded inside chat prompts.
Cloudflare Firewall for AI intercepted all payloads before they reached the NovaMind backend.
/api/v1/training-data — attempting JNDI callback to external infrastructure to
exfiltrate model weights. Spring4Shell and Apache Struts RCE payloads appeared on
/admin and /login. SSRF probes targeting
169.254.169.254 (cloud metadata endpoint) were also detected.
| Source Origin | DigitalOcean App Platform — single origin, rotating spoofed IPs via X-Forwarded-For |
| TLS Fingerprint (JA4) | t13d1812h1_85036bcba153_b26ce05bbdd6 — Python requests library, constant across all traffic |
| Bot Score | 29 / 100 — Source: Heuristics — Tags: ["scraper", "python"] |
| WAF SQL Injection Score | > 60 on all /api/* paths (Box 1) |
| WAF RCE Attack Score | > 90 on /api/v1/training-data, /admin, /login (Box 4) |
| AI Injection Score | FirewallForAIInjectionScore: 100 — AISecurityInjectionScore: 100 (Box 3) |
| Attack Duration | 4-phase campaign — recon → bot evasion → AI injection → full breakout |
No incidents in the past 90 days.