Topic

Langflow

🇯🇵Aug 5

Prepare for Summer Vacation: Patch Tuesday Overlaps with Obon Holiday Week Raises Risks

As August approaches and organizations enter summer vacation season, many will face a challenging overlap between Microsoft's Patch Tuesday and Japan's Obon holiday week in 2026. System administrators and security teams are often unavailable during extended breaks, leading to slower detection, reporting, and remediation of threats. Ransomware campaigns frequently target periods such as evenings, weekends, and consecutive holidays when response times are delayed. Experts recommend completing software updates on servers, network devices, and endpoints before departure to close known vulnerabilities. Security product definition files should be refreshed, unused systems powered down after risk assessment, and basic controls verified in advance. The advisory from Security NEXT highlights that dispersed vacation schedules in some organizations still leave concentrated risk windows for others.

Security NEXT•Vulnerabilities & Exploits
🇯🇵Aug 5

CISA Adds Three Actively Exploited Vulnerabilities to KEV Catalog Affecting Langflow, Apache Tomcat and N-central

The U.S. Cybersecurity and Infrastructure Security Agency has added three known exploited vulnerabilities to its KEV catalog, urging federal agencies to apply patches by August 7, 2026. CVE-2026-9198 affects the AI application development platform Langflow and allows unauthenticated attackers to chain API calls, obtain tokens, and execute arbitrary code. CVE-2026-34486 impacts Apache Tomcat and enables bypass of the EncryptInterceptor, leaving cluster node communications unencrypted. CVE-2026-18556 in N-able N-central permits authentication bypass through alternate channels, while an incomplete fix introduced CVE-2026-18577, which was added to the catalog one day earlier. All three issues have confirmed exploitation in the wild.

Security NEXT•Vulnerabilities & Exploits
🇷🇺Aug 4

DeepSeek-Powered Telegram Bot Attempts Autonomous Attacks on 460 Targets but Achieves Zero Successes

Researchers from Unit 42 at Palo Alto Networks recovered the full activity log of an autonomous AI agent built with the Hermes Agent framework and the DeepSeek model. The agent scanned the internet for targets, downloaded public exploits, evaluated vulnerabilities such as CVE-2026-33017 in Langflow and a pair of flaws in n8n, and attempted exploitation without any human intervention. Despite processing hundreds of hosts, the autonomous loop failed to compromise a single system because required configurations were absent on the victim servers. Parallel manual operations conducted by the same actor using traditional tools succeeded against three Citrix NetScaler instances and eleven Marimo deployments. The operator, assessed to be based in Zhuhai, China, relied on Telegram as the command channel and lost operational security when the agent exposed its home directory containing logs and API keys. The case demonstrates both the current limitations of LLM-driven attack agents and the low barrier to entry created by open-source agent frameworks paired with permissive models.

Habr•AI Security
🇷🇺Jul 12

Critical CVSS 10.0 Vulnerabilities in Joomla SP Page Builder and Page Builder CK Enable One-Click Unauthenticated File Upload and Full Site Takeover

U.S. authorities have warned about three actively exploited vulnerabilities added to CISA’s Known Exploited Vulnerabilities catalog, urging immediate patching. The most severe issues, CVE-2026-48908 and CVE-2026-56290, affect Joomla extensions SP Page Builder and Page Builder CK respectively, both scoring 10.0 and allowing unauthenticated attackers to upload and execute arbitrary PHP files for complete site compromise. A third flaw, CVE-2026-55255 (CVSS 9.9), impacts the Langflow AI application platform and permits authenticated attackers to hijack other users’ processes and access sensitive secrets. All three vulnerabilities are already being used in real-world attacks, though CISA has not disclosed attacker identities or victim counts. Federal agencies must remediate under BOD 26-04, while all organizations are advised to check for vulnerable components, apply fixes, and review logs for prior intrusions.

securitylab_n•Vulnerabilities & Exploits