<?xml version='1.0' encoding='utf-8'?>
<rss version="2.0"><channel><title>Cybersecurity Tracker: Langflow Watch</title><link>https://cybersecuritytracker.ai/?stack=1</link><description>Stories and vulnerabilities involving Langflow.</description><lastBuildDate>Sun, 26 Jul 2026 22:32:52 GMT</lastBuildDate><item><title>CISA Adds Four Known Exploited Vulnerabilities to Catalog</title><link>https://cisa.gov/news-events/alerts/2026/07/21/cisa-adds-four-known-exploited-vulnerabilities-catalog</link><guid isPermaLink="false">cst-2931</guid><description>CISA added four vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on active exploitation evidence: CVE-2021-27137 (DD-WRT buffer overflow), CVE-2026-0770 (Langflow control sphere inclusion), CVE-2026-63030 (WordPress interpretation conflict), and CVE-2026-60137 (WordPress SQL injection). Binding Operational Directive 26-04 requires federal agencies to prioritize patching KEV-listed vulnerabilities on publicly exposed assets, while CISA encourages all organizations to adopt risk-based vulnerability management practices.</description><pubDate>Tue, 21 Jul 2026 12:00:00 GMT</pubDate></item><item><title>13th July – Threat Intelligence Report</title><link>https://research.checkpoint.com/2026/13th-july-threat-intelligence-report</link><guid isPermaLink="false">cst-2410</guid><description>A weekly threat intelligence bulletin covering significant incidents from July 13 including data breaches at AssuranceAmerica (7 million people), Latvijas Valsts Meži (ransomware exploiting two-year-old vulnerability), Injective Labs (supply chain compromise via malicious npm packages), and Moody Bible Institute (2.3 million donors and supporters). The report also details emerging AI threats such as autonomous ransomware using language models and malicious code injection attacks against coding agents, along with critical vulnerabilities in Tenda routers, Linux KVM hypervisor, U-Boot bootloader, and Opera GX browser.</description><pubDate>Mon, 13 Jul 2026 13:06:08 GMT</pubDate></item><item><title>Attackers using Langflow flaw for credential harvesting (CVE-2026-55255)</title><link>https://helpnetsecurity.com/2026/07/08/langflow-vulnerability-cve-2026-55255-exploited</link><guid isPermaLink="false">cst-2176</guid><description>The US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-55255 to its Known Exploited Vulnerabilities catalog after the Sysdig Threat Research Team observed active exploitation of a Langflow vulnerability. Langflow is an open-source framework for building AI agents and workflows used by developers, enterprises, and service providers. Attackers are leveraging this flaw for credential harvesting.</description><pubDate>Wed, 08 Jul 2026 14:03:04 GMT</pubDate></item><item><title>JadePuffer ransomware used AI agent to automate entire attack</title><link>https://bleepingcomputer.com/news/security/jadepuffer-ransomware-used-ai-agent-to-automate-entire-attack</link><guid isPermaLink="false">cst-4</guid><description>Researchers identified what they believe is the first documented case of a ransomware operation, JadePuffer, that was conducted entirely by a large language model (LLM) agent. The operation leveraged automation to execute the attack without traditional human intervention at each step.</description><pubDate>Sat, 04 Jul 2026 14:16:38 GMT</pubDate></item><item><title>Langflow RCE Exploited to Deploy Monero Miner on Exposed AI App Endpoints</title><link>https://thehackernews.com/2026/06/langflow-rce-exploited-to-deploy-monero.html</link><guid isPermaLink="false">cst-59</guid><description>Threat actors are actively exploiting a critical unauthenticated remote code execution vulnerability in Langflow to deploy Monero miners on exposed AI application endpoints. The attacks target CVE-2024-33017, which has a CVSS score of 9.3, and indicate broad scanning for vulnerable instances. The activity demonstrates continued weaponization of the Langflow flaw for cryptocurrency mining purposes.</description><pubDate>Tue, 30 Jun 2026 15:47:20 GMT</pubDate></item><item><title>May 2026 CVE Landscape</title><link>https://recordedfuture.com/blog/may-2026-cve-landscape</link><guid isPermaLink="false">cst-1953</guid><description>In May 2026, Insikt Group identified 41 high-impact vulnerabilities requiring prioritized remediation, representing an 11% increase from April. These vulnerabilities affected 20 vendors, with 21 included in CISA's Known Exploited Vulnerabilities catalog, 19 detected via honeypot data, and one reported by a vendor. Notably, 12 vulnerabilities enabled remote code execution, public proof-of-concept exploits were available for 32 of them, and five were first disclosed between 2008 and 2010, demonstrating continued exploitation of long-standing weaknesses.</description><pubDate>Mon, 08 Jun 2026 00:00:00 GMT</pubDate></item><item><title>March 2026 CVE Landscape: 31 High-Impact Vulnerabilities Identified, Interlock Ransomware Group Exploits Cisco FMC Zero-Day</title><link>https://recordedfuture.com/blog/march-2026-cve-landscape</link><guid isPermaLink="false">cst-1981</guid><description>Insikt Group identified 31 high-impact vulnerabilities actively exploited in March 2026, with 29 rated as very critical. The affected products span major vendors including Cisco, Microsoft, Google, ConnectWise, Citrix, and others, with Microsoft and Apple accounting for approximately 32% of the total. Notable findings include the Interlock ransomware group exploiting a Cisco Firewall Management Center zero-day, the continued exploitation of a nine-year-old Hikvision vulnerability, and public proof-of-concept exploits available for 10 of the 31 vulnerabilities.</description><pubDate>Mon, 13 Apr 2026 00:00:00 GMT</pubDate></item></channel></rss>