One Unpatched Langflow Endpoint Could Hand Attackers Your OpenAI and AWS Keys

Attackers are exploiting a critical Langflow endpoint to steal OpenAI keys, AWS credentials and administrator secrets. Patching is only the first step.

Attackers are exploiting a critical Langflow endpoint to steal OpenAI keys, AWS credentials and administrator secrets. Patching is only the first step.

Infostealers are stealing active Claude sessions, bypassing the need to defeat passwords or multi-factor authentication.

AshAI disclosed six vulnerabilities, including a CVSS 10 flaw that compiled attacker-controlled prompt content as Elixir before any model request.

More than 130 organisations warn that defenders have only months to prepare, but their voluntary pledge includes no deadlines.

Cisco warns that model publishers and country labels can hide inherited weights, training data and upstream dependencies.

NVIDIA fixed 18 NemoClaw and OpenShell vulnerabilities, including two network-reachable 9.9 flaws that can escape the sandbox. OpenShell 0.0.34 and specific NemoClaw commits contain the fixes.

Linux Foundation's TRACE project does not keep AI agents inside the sandbox. It creates hardware-attested records of what ran, under which policy and which tools were called.

Ray CVE-2025-62593 turns a malicious browser visit into AI infrastructure code execution. Patch Ray and replace browser trust with authentication.

Attackers are exploiting MLflow CVE-2026-64849 to turn exposed AI engineering services into a route to cloud metadata, internal systems and workload identity.

As artificial intelligence moves from answering questions to taking actions, organisations need to rethink where capability ends and authority begins. For the last few years, most people have interacted with artificial intelligence in a fairly contained way. You ask a…