Hackers Exploit Langflow RCE Flaw to Harvest OpenAI and AWS Credentials
Threat actors are actively exploiting a critical remote code execution vulnerability in Langflow, a low-code platform used for building AI-powered applicatio...
Articles mapped to MITRE ATT&CK techniques. Select a technique to view matching articles.
497 articles found
Threat actors are actively exploiting a critical remote code execution vulnerability in Langflow, a low-code platform used for building AI-powered applicatio...
Forescout researchers used Claude AI to port a remote code execution exploit between WAGO PLC models. The post Experiment: Porting a PLC Exploit With AI Take...
View CSAF Summary Successful exploitation of these vulnerabilities could crash the device being accessed; an out-of-bounds write condition may allow remote c...
U.S.
A public proof-of-concept (PoC) repository has garnered attention for a pre-authentication remote code execution chain targeting Microsoft Exchange Server. T...
Security researchers have demonstrated how flaws in the AI shopping assistant of a major unnamed U.S.
This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exp...
This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exp...
This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exp...
This vulnerability allows remote attackers to execute arbitrary code on affected installations of pdfforge PDF Architect. User interaction is required to exp...
Langflow 1.8.
PaperCut servers are under active attack, while 47% of tracked installations still run unpatched versions vulnerable to remote code execution. PaperCut, the ...
A critical vulnerability in Gogs, the self-hosted Git service, could allow authenticated attackers to execute commands on the server by abusing path traversa...
The vulnerability, present in GiveWP versions up to 4.16.
The vulnerabilities, tracked as CVE-2026-76639 and CVE-2026-76640, present distinct attack vectors. CVE-2026-76639 involves a network-adjacent path through c...
Over 8,300 Internet-exposed Gitea instances are still unpatched against a critical security flaw exploited in ongoing remote code execution attacks, accordin...
OpenAI’s ExploitGym evaluation environment reportedly became the site of a large-scale, unsanctioned multi-agent campaign after hundreds of models found ways...
Security researcher Olivier Laflamme has disclosed two independent root remote code execution (RCE) chains affecting the Unitree G1 EDU, including a Bluetoot...
Security researcher Boschko has revealed two vulnerabilities in Unitree’s G1 humanoid robot that can be exploited to achieve unauthenticated remote code exec...
Credit: Hacktron Vercel has released security patches for two critical-severity vulnerabilities in the Next.js web framework, both of which allow unauthentic...