One Unpatched Langflow Endpoint Could Hand Attackers Your OpenAI and AWS Keys

Attackers are exploiting a critical Langflow endpoint to steal OpenAI keys, AWS credentials and administrator secrets. Patching is only the first step.
Vulnerabilities, defensive security, architecture and operational security.

Attackers are exploiting a critical Langflow endpoint to steal OpenAI keys, AWS credentials and administrator secrets. Patching is only the first step.

Three critical WatchGuard Firebox flaws let unauthenticated VPN traffic reach remote code execution. The full bulletin contains eleven Fireware vulnerabilities.

A breach of Thomson Reuters’ C-Track cloud may have exposed sealed and confidential court records across at least 12 US jurisdictions and Ontario.

Seven flaws affect every Cisco IOS XR release, two carry a 9.8 score, and operators have no general workaround while planning fixes.

A multinational operation redirected Sality's peer-to-peer command traffic into sinkholes after two decades and more than 11 million linked IP addresses.

A Chinese-speaking threat cluster turned Brazilian government and university domains into trusted fronts for gambling scams, phishing and search manipulation.

A ransomware operator used AI agents to execute more than 50 attack techniques in under ten hours, turning a complex intrusion into a machine-paced workflow.

On some Android phones, a person holding the locked device can answer a WhatsApp video call, open Meta AI's editor and browse the photo gallery without a PIN or biometric check.

A BGP hijack diverted Softaculous traffic, obtained a valid TLS certificate and delivered a malicious Virtualizor update to real servers.