organization · 4 records
n8n

JADEPUFFER group targets AI infrastructure using new ENCFORGE ransomware strain
A threat actor known as JADEPUFFER deployed a new Go-based ransomware strain called ENCFORGE targeting AI model files and infrastructure after exploiting a remote code execution vulnerability in Langflow.

New exploit allows users to impersonate domain controllers in Active Directory
Researchers published an exploit for a vulnerability in Microsoft's Active Directory Certificate Services that enables low-privileged users to impersonate Domain Controllers.

n8n patches high severity sandbox escape vulnerability in automation platform
n8n has patched a high-severity expression-sandbox escape vulnerability that could allow authenticated workflow editors to execute operating-system commands on the server running the automation platform.

New NadMesh botnet targets exposed cloud credentials and API keys
A new Go botnet named NadMesh is targeting exposed AI and development services to harvest cloud credentials, Kubernetes tokens, and API keys, with operators claiming thousands of compromised AWS keys.