AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack

A sophisticated AI-powered cyberattack has exploited a known vulnerability in Langflow, an open-source Python library used for image processing and deep learning tasks, to automate database ransomware attacks on unsuspecting organizations. The attack highlights the increasingly complex threat landscape and underscores the need for vigilance against emerging security risks. The vulnerability, discovered by researchers last … Read more

CISA: Microsoft SharePoint RCE flaw now actively exploited

A Critical SharePoint Flaw is Being Actively Exploited by Hackers, Says CISA The US Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning that a high-severity vulnerability in Microsoft’s SharePoint platform is being exploited by attackers. This flaw, tracked as CVE-2026-45659, allows hackers to execute arbitrary code on unpatched SharePoint servers with just low-level … Read more

Cisco finally confirms attackers exploiting Unified CM flaw

Attackers are now exploiting a critical vulnerability in Cisco’s Unified Communications Manager (Unified CM) software, despite patches being released just over a month ago. This development highlights the ongoing threat of cyberattacks on business communication systems and emphasizes the importance of prompt patching and security measures. Unified CM is a central control system used by … Read more

FortiBleed Credential Theft Linked to INC and Lynx Ransomware Operations

A devastating credential theft campaign, dubbed FortiBleed, has been linked to notorious ransomware operations Inc and Lynx. The attack, which leverages vulnerabilities in enterprise security solutions, has compromised sensitive information from numerous organizations worldwide, leaving businesses scrambling to contain the damage. At its core, FortiBleed exploits a specific weakness in Fortinet’s SSL/TLS (Secure Sockets Layer/Transport … Read more

AI Agent Exploits Langflow RCE to Automate Database Ransomware Attack

A sophisticated AI-powered attack has leveraged a previously unknown vulnerability in Langflow, an open-source framework for natural language processing, to automate a database ransomware assault on several high-profile targets. The AI agent exploited the Remote Code Execution (RCE) flaw, dubbed “LangFlow-1,” to breach sensitive databases and encrypt crucial data. The exploitation of LangFlow-1 marks a … Read more

Safe Events Start With Threat Intel and Digital Security

Major events like sports championships, festivals, and government celebrations attract global attention, but they also come with significant cybersecurity risks. These threats don’t appear out of nowhere; rather, they’re often well-planned and executed by malicious actors who begin gathering intelligence months or even years in advance. When we think about event security, our minds often … Read more

‘Phantom Squatting’: An Emerging AI-Driven Supply Chain Threat

Cybercriminals are using a new and insidious attack vector called “phantom squatting” to threaten the software supply chain. By exploiting the tendency of large language models (LLMs) to “hallucinate” or generate fictional web domains for legitimate brands, attackers can register nonexistent domains linked to these brands, creating a perfect trap for unsuspecting users. The technique … Read more

Medtronic notifies customers impacted by ShinyHunters data breach

Medtronic Hit by ShinyHunters Data Breach, Exposing Sensitive Customer Information to Hackers Medical device firm Medtronic has notified customers that their personal data was compromised in a recent data breach attributed to the notorious hacking group ShinyHunters. The company’s IT systems were breached between April 13 and April 19, allowing hackers to access sensitive customer … Read more

SharePoint RCE CVE-2026-45659 Added to CISA KEV After Active Exploitation

A Critical SharePoint Vulnerability Has Been Actively Exploited, Leaving Thousands of Organizations Exposed The US Cybersecurity and Infrastructure Security Agency (CISA) has added a newly disclosed vulnerability, CVE-2026-45659, to its Known Exploitable Vulnerabilities catalog. This remote code execution (RCE) flaw affects SharePoint, a widely used collaboration platform, and has already been exploited by attackers in … Read more

New ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit Repos

A new and highly sophisticated malware strain, dubbed ChocoPoC RAT, has been discovered preying on vulnerability researchers who use Proof of Concept (PoC) exploit repositories online. The attackers behind this malicious campaign are targeting researchers who work with vulnerable software, luring them into downloading fake PoC exploits that secretly install the ChocoPoC Remote Access Trojan … Read more