company · 4 records
Langflow

JADEPUFFER group targets AI infrastructure using new ENCFORGE ransomware strain
A threat actor known as JADEPUFFER deployed a new Go-based ransomware strain called ENCFORGE targeting AI model files and infrastructure after exploiting a remote code execution vulnerability in Langflow.

Ruby on Rails releases security patches for critical Active Storage vulnerability
Ruby on Rails has released fixes for a critical Active Storage vulnerability that could let unauthenticated attackers read arbitrary files from application servers through crafted image uploads.

New NadMesh botnet targets exposed cloud credentials and API keys
A new Go botnet named NadMesh is targeting exposed AI and development services to harvest cloud credentials, Kubernetes tokens, and API keys, with operators claiming thousands of compromised AWS keys.

CISA issues directive on actively exploited Langflow remote code execution vulnerability
CVE-2026-0770 disclosed: Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected ins