Related Threat Clusters
-
Critical RCE Vulnerability in IBM Langflow Under Active Exploitation
IBM Langflow OSS is facing a critical remote code execution (RCE) vulnerability, tracked as CVE-2026-9198, which allows unauthenticated attackers to execute arbitrary code on default deployments. The vulnerability…
14 articles · Updated August 5, 2026 -
Critical RCE Vulnerability in Marimo Exploited Within 10 Hours of Disclosure
A critical pre-authentication remote code execution (RCE) vulnerability in Marimo, an open-source Python notebook platform, was disclosed on April 8, 2026, and exploited within 9 hours and 41 minutes. The vulnerability,…
16 articles · Updated April 12, 2026 -
ShinyHunters Exploits Oracle PeopleSoft Zero-Day Vulnerability
A critical zero-day vulnerability (CVE-2026-35273) in Oracle PeopleSoft has been exploited by the ShinyHunters group, leading to breaches of over 100 organizations, primarily in the education sector. The vulnerability…
65 articles · Updated June 11, 2026 -
Langflow RCE Vulnerability Leads to Monero Cryptominer Deployment
Threat actors are exploiting CVE-2026-33017, a critical unauthenticated remote code execution vulnerability in Langflow, to compromise exposed AI application servers. This exploitation allows attackers to deploy a…
2 articles · Updated June 30, 2026 -
Critical Vulnerabilities in Dell Wyse Management Suite Enable Remote Code Execution
Dell Technologies has disclosed critical vulnerabilities in its Wyse Management Suite (WMS) that allow remote attackers to execute arbitrary code. The vulnerabilities, identified as CVE-2026-41120 and CVE-2026-49506,…
4 articles · Updated June 29, 2026 -
Langflow CVE-2026-33017 Exploited for AWS Key Theft and Botnet Deployment
The Langflow vulnerability CVE-2026-33017 is being actively exploited to steal AWS keys and create a botnet known as 'KeyHunter.' This vulnerability allows for remote code execution on unpatched Langflow instances,…
3 articles · Updated May 14, 2026 -
Critical Langflow RCE Vulnerability Exploited Within 20 Hours
A critical vulnerability in Langflow, tracked as CVE-2026-33017, allows unauthenticated remote code execution (RCE) via the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint. This flaw was exploited within 20 hours…
17 articles · Updated March 20, 2026 -
Critical RCE Vulnerability in Marimo Exploited Within 10 Hours of Disclosure
On April 8, 2026, a critical pre-authenticated remote code execution vulnerability (CVE-2026-39987) was disclosed in Marimo, an open-source Python notebook platform. The flaw allows unauthenticated attackers to gain a…
2 articles · Updated June 9, 2026 -
LiteLLM Python Package Compromised in Major Supply Chain Attack by TeamPCP
On March 24, 2026, two malicious versions of the LiteLLM Python package (1.82.7 and 1.82.8) were published on PyPI, containing credential-stealing malware. The attack, attributed to the TeamPCP threat group, exploited…
53 articles · Updated March 24, 2026 -
Mistic Malware Targets Microsoft Endpoint with Stealthy DLL Sideloading Technique
The Mistic malware, a newly identified Windows backdoor, has been active since April 2026, utilizing DLL sideloading to infiltrate enterprise environments. It exploits a legitimate executable, MpExtMs.exe, to load a…
2 articles · Updated June 30, 2026
Recent Intelligence Reports
- Critical RCE in IBM Langflow Triggers CISA Emergency Deadline — Forkast.News · August 6, 2026
- BleepingComputer summarised the finding — www.bleepingcomputer.com · August 2, 2026
- Unit 42 Ties DeepSeek Agent to 460+ Autonomous Hack Attempts — Aiweekly.Co · August 1, 2026
- DeepSeek Ran Autonomous Cyberattacks That Claude and OpenAI Safety Controls Blocked — Techtimes · August 1, 2026
- Mistic Malware Blends Into Microsoft Endpoint Components Using Malicious EndpointDlp.dll — Gbhackers · June 30, 2026
- Langflow RCE Vulnerability Exploited to Deploy Monero Cryptominer on Exposed AI Servers — Gbhackers · June 29, 2026
- Critical Dell Wyse Management Suite Vulnerabilities Let Attackers Execute Remote Code — Gbhackers · June 29, 2026
- Agentic Red-Team Tools Flaws Let Hackers Steal API Keys, Escape Sandboxes, and ... — Gbhackers · June 25, 2026