Curated Cyber Threat Intelligence
Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports
Filtered Reports
2 / 2 results
criticalbug_reportVulnerabilitybug_reportVulnerability
Langflow CVE-2026-0768 exploited to steal OpenAI and AWS credentials
Langflow versions 1.4.2 and earlier. The vulnerability exists in the code validator of the custom component editor's validate endpoint. Patched in version 1.11.6.
CVE-2026-07681 Sep · 15:54 UTC
criticalbug_reportVulnerabilitybug_reportVulnerability
Langflow and Ruby on Rails flaws exploited for credential theft and C2
Langflow (CVE-2026-0768, CVSS 9.8) - arbitrary Python code execution as root via improper input validation. Ruby on Rails (CVE-2026-66066 aka KindaRails2Shell, CVSS 9.5) - arbitrary file read and RCE affecting applications using libvips for Active St…
CVE-2026-07681 Sep · 05:22 UTC