#Langflow
14 stories taggedLangflow.

Langflow's Built-In Testing Tool Has No Password and Attackers Are Using It Right Now
Three critical flaws in the popular AI workflow builder let attackers run any code they like on your server, as root, without logging in. CISA ordered federal agencies to patch by May 26. Attackers are not waiting.

Hackers Are Actively Exploiting a Critical Flaw in the AI Builder Langflow
A software vulnerability scored at near-maximum severity is being used right now to break into Langflow servers and steal credentials. Over 360 attacks hit tracking sensors in the UK in a single day.

CISA Adds Three Actively Exploited Bugs to Its Must-Patch List
A critical Langflow flaw joins Apache Tomcat and N-central issues on the U.S. government's Known Exploited Vulnerabilities catalog after evidence of live attacks.

US government orders emergency fix for Langflow AI tool after hackers exploit it in the wild
CVE-2026-0770 lets attackers take over Langflow servers without a password. Federal agencies have until Friday to patch.

ENCFORGE: The Ransomware That Goes After AI Brains, Not Your Spreadsheets
Sysdig says the same crew that broke into a Langflow server earlier this month is back, and this time it encrypts model weights instead of office files.

AI-hunting ransomware 'EncForge' locks up model files as JadePuffer agent adapts on the fly
The autonomous attacker rewrote its own delivery script six times in five minutes before encrypting a Langflow server's machine-learning assets.

AI Agents Are Now Running Entire Cyberattacks, Start to Finish
Two separate investigations show that criminals are handing whole attack campaigns to artificial intelligence, cutting the time it takes to ransack a company from weeks to hours.

U.S. Government Gives Agencies Two Weeks to Patch Four Actively Exploited Flaws
Critical security holes in Adobe ColdFusion, Langflow, and Joomla extensions are already being used by attackers. Federal agencies have until July 10 to fix them.

US cyber agency gives federal staff four days to patch Langflow AI tool being actively hacked
CISA added an authorisation bypass in the popular AI-agent builder Langflow to its must-patch list after Sysdig spotted attackers stealing cloud keys and hijacking servers.

CISA Flags Four Live-Exploited Bugs in Adobe, Joomla and Langflow
The US cyber agency gave federal agencies until early December to patch a critical Adobe ColdFusion flaw and three others already being abused in the wild.

An AI Agent Broke Into a Server, Taught Itself to Adapt, and Left a Ransom Note
Security firm Sysdig says it has documented the first fully autonomous AI-driven ransomware attack, where a program called JadePuffer broke into a database, encrypted thousands of records, and demanded Bitcoin payment without a human criminal directing any step.

An AI Agent Ran a Ransomware Attack by Itself. Here's What That Means.
Criminals used an AI tool called Langflow to let a machine plan and carry out a multi-step ransomware intrusion without a human guiding every move, a shift that could make attacks faster and cheaper to run at scale.

Sysdig Flags 'JADEPUFFER' as First End-to-End AI-Run Ransomware Attack
Researchers say a large language model handled intrusion, lateral movement and destruction of a production database without a human at the keyboard.

Langflow RCE Is Back on the Menu — This Time for a Monero Miner
Attackers are still pillaging exposed Langflow instances through CVE-2026-33017, turning forgotten AI workflow servers into XMR mining rigs.