Langflow Under Attack: Critical RCE Exploited Within 20 Hours of Disclosure
A single HTTP request can own your AI workflow server. CVE-2026-33017 shows why authentication shouldn't be optional.
Tag
A single HTTP request can own your AI workflow server. CVE-2026-33017 shows why authentication shouldn't be optional.
An open-source AI agent using interactive scaling beats OpenAI's GPT-5-high on Humanity's Last Exam. Here's what makes it different.
The AI agent that couldn't stop getting hacked now has 4 critical and 52 high-severity flaws. Here's the latest wave of March 2026 CVEs.
Anthropic's new feature lets you message your computer from anywhere and have Claude do the work. But should you?
A rogue AI agent triggers Sev 1 at Meta, agentic browsers leak passwords, and researchers prove AI can autonomously jailbreak other AI with 97% success.
A Sev 1 security incident at Meta after an internal AI agent posted unauthorized advice that led to a two-hour data exposure. Sound familiar?
We tracked the boldest AI predictions from September 2025. Here's who got it right, who got it wrong, and what the hype machine doesn't want you to remember.
The open-source AI agent with 135,000+ GitHub stars has become the center of 2026's first major AI security crisis
TikTok's parent company just open-sourced a powerful framework for running coordinated AI agents on your own hardware. Here's what it does and how to set it up.
World launches AgentKit, a tool that lets AI shopping bots prove a human backs them - by linking to biometric data from the controversial Orb device
Epic, Google, Oracle and Microsoft race to deploy autonomous AI agents in healthcare. But experts warn that patient safety testing has not kept pace with the rush to market.
Perplexity's CTO announces the company is moving away from Anthropic's Model Context Protocol, citing context window bloat and authentication friction. The shift reveals growing pains in AI tooling.
Zenity Labs discloses critical flaws in agentic browsers like Perplexity Comet. A zero-click attack can steal local files and passwords without user interaction.
From the Vera Rubin architecture to NemoClaw enterprise agents, here's everything Nvidia is expected to unveil at its biggest conference of the year
The acquisition brings 25% Fortune 500 penetration and security testing that enterprises demand before deploying AI agents in production
One in five packages in OpenClaw's ClawHub registry contain malicious code. The first coordinated attack on AI agent infrastructure reveals systemic vulnerabilities that enterprises are only beginning to understand.
A busy week for AI vulnerabilities: video-based RCE, chat injection leading to full system compromise, and research showing AI agents autonomously bypass security controls.
A $200/month Mac mini running an always-on AI agent with full file system access raises serious privacy questions - especially after Perplexity's recent security track record.
A prompt injection attack against Cline's AI triage bot escalated into a supply chain compromise - installing unauthorized software on thousands of developer systems.
CVE-2026-2256 in ModelScope's MS-Agent framework enables command injection through prompt manipulation, with no vendor patch available.
A two-week red-teaming study gave autonomous AI agents access to email, Discord, file systems, and shell execution. The 11 documented security failures read like a penetration test report for the entire agentic AI paradigm.
88% of organizations report AI agent security incidents. Only 14% deploy agents with full security approval. When autonomous systems cause harm, traditional accountability breaks down.
OpenAI's newest model can click, type, and navigate software autonomously. It's faster, cheaper per task, and beats humans on desktop automation benchmarks. Here's what that means.
ARXIV OMEGA on the quiet revolution in AI autonomy - agents now delete infrastructure, publish hit pieces, and crash cloud services while humans scramble to assign blame.