Related Threat Clusters
-
Critical RCE Vulnerability in IBM Langflow Under Active Exploitation
IBM Langflow OSS is facing a critical remote code execution (RCE) vulnerability, tracked as CVE-2026-9198, which allows unauthenticated attackers to execute arbitrary code on default deployments. The vulnerability…
14 articles · Updated August 5, 2026 -
CISA Warns of Critical Exploits in Langflow, Tomcat, and N-central Flaws
CISA has added critical vulnerabilities in IBM Langflow, Apache Tomcat, and N-able N-central to its Known Exploited Vulnerabilities catalog, with a deadline for federal agencies to patch by August 7, 2026. The Langflow…
2 articles · Updated August 7, 2026 -
Russian Hackers Target Networks via RDP, VPNs, and Supply Chains
Russian state-aligned threat groups are increasingly exploiting Remote Desktop Protocol (RDP), Virtual Private Networks (VPNs), and supply chain vulnerabilities to gain initial access to networks across various sectors,…
3 articles · Updated May 22, 2026 -
Iranian APT Groups Target Israeli Organizations with Modular C2 Frameworks
In 2026, Iranian APT groups, notably Cavern Manticore and OilRig, have intensified cyber operations against Israeli organizations, primarily in the IT and government sectors. Cavern Manticore employs a modular…
10 articles · Updated July 6, 2026 -
Multiple Critical Vulnerabilities Exploited in SonicWall and SharePoint Systems
In July 2026, several critical vulnerabilities were exploited, impacting SonicWall SMA1000 appliances and SharePoint servers. Two zero-day vulnerabilities, CVE-2026-15409 and CVE-2026-15410, were discovered in SonicWall…
2 articles · Updated July 28, 2026 -
Langflow CVE-2026-33017 Exploited for AWS Key Theft and Botnet Deployment
The Langflow vulnerability CVE-2026-33017 is being actively exploited to steal AWS keys and create a botnet known as 'KeyHunter.' This vulnerability allows for remote code execution on unpatched Langflow instances,…
3 articles · Updated May 14, 2026 -
Critical Langflow RCE Vulnerability Exploited Within 20 Hours
A critical vulnerability in Langflow, tracked as CVE-2026-33017, allows unauthenticated remote code execution (RCE) via the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint. This flaw was exploited within 20 hours…
17 articles · Updated March 20, 2026 -
Critical RCE Vulnerability in Marimo Exploited Within 10 Hours of Disclosure
On April 8, 2026, a critical pre-authenticated remote code execution vulnerability (CVE-2026-39987) was disclosed in Marimo, an open-source Python notebook platform. The flaw allows unauthenticated attackers to gain a…
2 articles · Updated June 9, 2026 -
Evolution of Chinese-Nexus Cyber Operations: Strategic Long-Term Threats
Recent research from Darktrace reveals the evolution of Chinese-nexus cyber operations over the past two decades, highlighting a shift from high-volume attacks to more strategic, identity-centric intrusions. This change…
381 articles · Updated April 2, 2026 -
Critical RCE Vulnerability Discovered in Flowise's MCP Implementation
Obsidian Security identified a critical one-click remote code execution (RCE) vulnerability in Flowise (CVE-2026-40933), affecting self-hosted deployments. The flaw allows attackers to execute arbitrary server-side code…
2 articles · Updated June 1, 2026
Recent Intelligence Reports
- Hackers Target AI Infrastructure With RCE and API Key Theft — Cypro · August 28, 2026
- Hacking your life with AI can get you hacked: How AI orchestration platforms ship RCE by design — Reddit · August 18, 2026
- Hacking your life with AI can get you hacked — Endorlabs · August 18, 2026
- Sysdig TRT - “JADEPUFFER: Agentic Ransomware for Automated Database Extortion” — www.sysdig.com · August 16, 2026
- CVE-2026-9198 — nvd.nist.gov · August 10, 2026
- CISA Adds Langflow, Tomcat, N-central Flaws to KEV Catalog — Aiweekly.Co · August 6, 2026
- Critical RCE in IBM Langflow Triggers CISA Emergency Deadline — Forkast.News · August 6, 2026
- Patch IBM Langflow now: CISA flags actively exploited CVE-2026 — Feeds.4Sysops · August 5, 2026