Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
11 / 11 results
criticalbug_reportVulnerabilityLangflow RCE vulnerability under active exploitation, patch immediately
Langflow (specific versions not disclosed in available data). The vulnerability affects Langflow installations exposed to network access. No CVE assigned yet.
criticalbug_reportVulnerabilityLangflow CVE-2026-0768 exploited to steal OpenAI and AWS credentials
Langflow versions 1.4.2 and earlier. The vulnerability exists in the code validator of the custom component editor's validate endpoint. Patched in version 1.11.6.
criticalbug_reportVulnerabilityLangflow and Ruby on Rails flaws actively exploited for RCE and C2
Langflow (CVE-2026-0768, CVSS 9.8): arbitrary Python code execution as root via improper input validation. Ruby on Rails (CVE-2026-66066 aka KindaRails2Shell, CVSS 9.5): unauthenticated arbitrary file read, secret leakage, and RCE in applications usi…
criticalbug_reportVulnerabilityCISA orders urgent patching of exploited Langflow RCE (CVE-2026-0770)
Langflow visual framework for building AI agents. All unpatched versions vulnerable. Affects unauthenticated remote attackers who can reach the /api/v1/validate/code endpoint. Federal agencies must patch by July 25, 2026.
highperson_alertThreat ActorNadMesh Botnet Targets AI Services for AWS and Kubernetes Credential Theft
NadMesh is a Go-based botnet operation discovered in early July that specializes in compromising cloud infrastructure credentials through exploitation of exposed AI and automation services.
criticalbug_reportVulnerabilityCISA orders federal patch for exploited Langflow auth bypass by Friday
Langflow visual AI agent framework - specific versions not disclosed in summary. Federal agencies mandated to patch; private sector should assume all unpatched instances at risk.
criticalperson_alertThreat ActorJADEPUFFER: First AI-Agent-Orchestrated Ransomware Attack
JADEPUFFER is a threat actor identified by Sysdig as the operator behind what is claimed to be the first fully AI-agent-orchestrated ransomware attack. The actor leveraged artificial intelligence agents to automate the entire attack lifecycle, repres…
criticalbug_reportVulnerabilityLangflow RCE (CVE-2026-33017) actively exploited for cryptomining
Langflow AI application framework, all exposed endpoints vulnerable to unauthenticated remote code execution. Specific affected versions not disclosed; assume all unpatched instances at risk.
highbug_reportVulnerabilityActive exploitation of path traversal in Langflow AI platform
Langflow AI development platform. Specific affected versions not disclosed. Impacts internet-exposed Langflow servers vulnerable to arbitrary file write via path traversal (CVE-2026-5027).
criticalbug_reportVulnerabilityLangflow path traversal flaw (CVE-2026-5027) exploited for RCE
Langflow open-source low-code AI platform, all unpatched versions. Vulnerability allows unauthenticated path traversal leading to arbitrary file write and remote code execution.
criticalbug_reportVulnerabilityCISA: Langflow and Trend Micro Apex One flaws actively exploited
Langflow (CVE-2025-34291, CVSS 9.4, origin validation error) and Trend Micro Apex One (CVE unspecified). Both products confirmed under active exploitation. Specific affected versions not disclosed in summary.