Tag

#cve-2025-3248

6 stories taggedcve-2025-3248.

Illustration: A glowing network of interconnected nodes and data pipelines rendered in deep blue and amber
Vulnerabilities

Langflow's Built-In Testing Tool Has No Password and Attackers Are Using It Right Now

Three critical flaws in the popular AI workflow builder let attackers run any code they like on your server, as root, without logging in. CISA ordered federal agencies to patch by May 26. Attackers are not waiting.

4 min read
Illustration: a dim data centre aisle, rack-mounted servers glowing with cool blue status lights
Ransomware

AI-hunting ransomware 'EncForge' locks up model files as JadePuffer agent adapts on the fly

The autonomous attacker rewrote its own delivery script six times in five minutes before encrypting a Langflow server's machine-learning assets.

4 min read
Illustration: A stark server room bathed in cold blue-white fluorescent light
AI Security

AI Agents Are Now Running Entire Cyberattacks, Start to Finish

Two separate investigations show that criminals are handing whole attack campaigns to artificial intelligence, cutting the time it takes to ransack a company from weeks to hours.

4 min read
Illustration: a server room corridor
Vulnerabilities

U.S. Government Gives Agencies Two Weeks to Patch Four Actively Exploited Flaws

Critical security holes in Adobe ColdFusion, Langflow, and Joomla extensions are already being used by attackers. Federal agencies have until July 10 to fix them.

3 min read
Illustration: A stark server room bathed in cold blue-white fluorescent light
AI Security

An AI Agent Broke Into a Server, Taught Itself to Adapt, and Left a Ransom Note

Security firm Sysdig says it has documented the first fully autonomous AI-driven ransomware attack, where a program called JadePuffer broke into a database, encrypted thousands of records, and demanded Bitcoin payment without a human criminal directing any step.

3 min read
Illustration: a dim server room aisle, one rack cabinet glowing faintly amber through mesh doors
Ransomware

Sysdig Flags 'JADEPUFFER' as First End-to-End AI-Run Ransomware Attack

Researchers say a large language model handled intrusion, lateral movement and destruction of a production database without a human at the keyboard.

3 min read
© 2026 Threat Vectr