Langflow Under Attack: Critical RCE Exploited Within 20 Hours of Disclosure
A single HTTP request can own your AI workflow server. CVE-2026-33017 shows why authentication shouldn't be optional.
Tag
A single HTTP request can own your AI workflow server. CVE-2026-33017 shows why authentication shouldn't be optional.
IEEE S&P research finds 10,000+ websites running vulnerable AI chatbot plugins. Attackers can forge conversations, hijack tools, and extract system prompts.
The AI agent that couldn't stop getting hacked now has 4 critical and 52 high-severity flaws. Here's the latest wave of March 2026 CVEs.
A rogue AI agent triggers Sev 1 at Meta, agentic browsers leak passwords, and researchers prove AI can autonomously jailbreak other AI with 97% success.
The open-source AI agent with 135,000+ GitHub stars has become the center of 2026's first major AI security crisis
A self-propagating malware campaign steals developer credentials via malicious VS Code extensions, then force-pushes cryptocurrency-stealing code into legitimate Python projects.
Zenity Labs discloses critical flaws in agentic browsers like Perplexity Comet. A zero-click attack can steal local files and passwords without user interaction.
One in five packages in OpenClaw's ClawHub registry contain malicious code. The first coordinated attack on AI agent infrastructure reveals systemic vulnerabilities that enterprises are only beginning to understand.
The acquisition brings 25% Fortune 500 penetration and security testing that enterprises demand before deploying AI agents in production
A busy week for AI vulnerabilities: video-based RCE, chat injection leading to full system compromise, and research showing AI agents autonomously bypass security controls.
A $200/month Mac mini running an always-on AI agent with full file system access raises serious privacy questions - especially after Perplexity's recent security track record.
Anthropic's Claude Opus 4.6 discovered 14 high-severity bugs in Firefox including a CVSS 9.8 JIT flaw, demonstrating that AI security research can find logic errors traditional tools overlook.
A prompt injection attack against Cline's AI triage bot escalated into a supply chain compromise - installing unauthorized software on thousands of developer systems.
CVE-2026-2256 in ModelScope's MS-Agent framework enables command injection through prompt manipulation, with no vendor patch available.
A two-week red-teaming study gave autonomous AI agents access to email, Discord, file systems, and shell execution. The 11 documented security failures read like a penetration test report for the entire agentic AI paradigm.
88% of organizations report AI agent security incidents. Only 14% deploy agents with full security approval. When autonomous systems cause harm, traditional accountability breaks down.
Most companies have no idea what their AI systems are actually doing. A CrowdStrike-backed startup thinks it can change that.
Zenity Labs reveals how a malicious calendar event could let attackers hijack Perplexity's Comet browser to exfiltrate local files and take over your 1Password account.
Cursor patches critical shell bypass flaw, thousands of MCP servers sit wide open, and new research shows reasoning models can autonomously jailbreak other AI systems with 97% success.
A patched Chrome vulnerability let malicious extensions hijack Gemini's access to your camera, microphone, and files. Here's what happened.
Veea releases a sub-millisecond security proxy for AI agents under MIT license as new research shows 88% of organizations have experienced agent security incidents.
Google and Cloudflare are deploying Merkle Tree Certificates to protect HTTPS against quantum computer attacks without breaking the internet
A veteran Google security engineer built a sandbox system that treats AI agents as fundamentally untrusted - and it could be the model for safe agent deployment.
A perfect 10.0 CVSS vulnerability in the popular workflow automation platform lets attackers hijack self-hosted instances used for AI agent automation without authentication.