threat-intel CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited The U.S. CISA has added three vulnerabilities to its KEV catalog, including a critical code injection flaw in Langflow, a Tomcat encryption bypass, and an authentication bypass in N-able N-central. These flaws are currently being actively exploited by a Chinese-speaking threat actor, leveraging AI tools to identify and… The Hacker News · Aug 5, 2026 Critical CVE-2026-9198CVE-2026-34486CVE-2026-18556CNvulnerabilitythreat-actorai
threat-intel Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks A Chinese-speaking threat actor, tracked as ‘KnYuan’ and ‘Knaithe’, utilized the Hermes Agent framework and DeepSeek to autonomously launch attacks against over 460 targets. The agent, leveraging Telegram, identified and… The Hacker News · Jul 31, 2026 High CVE-2026-3055CVE-2026-39987CVE-2026-33017CHautonomous attacksvulnerability exploitationtelegram
threat-intel ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories This week’s ‘ThreatsDay’ bulletin highlights a diverse range of security threats, including AI-powered hacking campaigns, ransomware attacks targeting Russia, and vulnerabilities in various software systems. Notably, a C… The Hacker News · Jul 30, 2026 High CVE-2026-33017CVE-2026-21858CVE-2025-68613RUCCHransomwaresupply chainphishing
threat-intel Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks A Chinese-speaking threat actor, operating under the aliases knaithe and KnYuan, is leveraging AI to conduct autonomous cyberattacks. Using the Hermes Agent framework and DeepSeek, they autonomously identified and exploi… Palo Alto Unit 42 · Jul 30, 2026 High CVE-2026-33017CVE-2026-21858CVE-2025-68613CNaiautonomousvulnerability
threat-intel New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack A new ransomware, ENCFORGE, is targeting AI model files and infrastructure, leveraging a vulnerability in Langflow (CVE-2025-3248) to gain remote code execution. The ransomware, developed by a threat actor linked to a pr… The Hacker News · Jul 21, 2026 High CVE-2025-3248CVE-2026-33017ransomwarelangflowdocker
threat-intel CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws The CISA has issued an urgent warning to federal agencies and all organizations regarding several actively exploited vulnerabilities in Adobe ColdFusion, Langflow, Joomla extensions, and CitrixBleed. These flaws, includi… SecurityWeek · Jul 8, 2026 Critical CVE-2026-48282CVE-2026-55255CVE-2026-33017vulnerabilityexploitationpatch
threat-intel CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added four actively exploited vulnerabilities to its KEV catalog, including flaws in Adobe ColdFusion, JoomShaper SP Page Builder, and Langflow. These… The Hacker News · Jul 8, 2026 High CVE-2026-48282CVE-2026-56290CVE-2026-55255INvulnerabilityrceidror
ransomware Langflow RCE Exploited to Deploy Monero Miner on Exposed AI App Endpoints A critical Remote Code Execution (RCE) vulnerability (CVE-2026-33017) in Langflow is being exploited by threat actors to deploy a Monero cryptocurrency miner on exposed AI application endpoints. The campaign, active from… The Hacker News · Jun 30, 2026 Critical CVE-2026-33017CVE-2025-3248NOrcemoneroai
vulnerability Path traversal flaw in AI dev platform Langflow exploited in attacks Attackers are actively exploiting CVE-2026-5027, a high-severity path traversal vulnerability in the AI development platform Langflow, to write arbitrary files on exposed servers. BleepingComputer · Jun 10, 2026 High CVE-2026-5027CVE-2026-0770CVE-2026-21445
vulnerability Unpatched Langflow Flaw CVE-2026-5027 Exploited for Unauthenticated RCE A critical vulnerability, CVE-2026-5027, in the Langflow low-code platform has been actively exploited, allowing for remote code execution due to a lack of input sanitization. This flaw, combined with unauthenticated aut… The Hacker News · Jun 10, 2026 Critical CVE-2026-5027CVE-2026-0770CVE-2026-33017USCAlow-codeairemote code execution