More on the topic...
Generating detailed summary...
Failed to generate summary. Please try again.
Langflow’s path-traversal flaw is now under active attack. Researchers found that its POST /api/v2/files endpoint doesn’t sanitize paths, so anyone can upload arbitrary files to a default Langflow server—even without credentials. That opens the door to remote code execution, data theft or lateral movement. If you run Langflow, lock down authentication or patch to the fixed release immediately.
ServiceNow’s Australia release had a misconfigured endpoint that let unauthenticated actors query customer tables. Exploitation began June 2 and affected only a subset of tenants in that region or in custom installs. ServiceNow patched the hole after bug-bounty reports in April and early June. Ivanti Sentry customers face a more severe risk: two critical bugs in versions 9.9 and 10.0 let unauthenticated attackers run commands as root or create admin accounts via a vulnerable Tomcat API. Ivanti says upgrade to Sentry 10.5.2, 10.6.2 or 10.7.1 now.
Anthropic’s built-in /security-review shows bias if it reviews code in the same session that wrote it. A new plugin forces a separate session but only checks diffs, so complex multi-file issues slip through. The author proved that manual reviews in fresh sessions catch more potential flaws. On the threat side, Anthropic mapped almost 14,000 LLM-enabled technique observations from 832 banned accounts against MITRE ATT&CK. Mid-risk actors used AI mostly for malware creation and obfuscation; highest-risk groups chained autonomous agent steps—reconnaissance, SSRF, SSH key harvesting, lateral movement—without human prompts. Defender guidance: monitor for multi-step AI orchestration, then speed up patch cycles.
Fraud rings are combining deepfakes, masks and injected video to beat liveness checks in banking and hiring flows. North Korean IT workers, a Vietnamese gang laundering $38.4 million and impersonators in Singapore, Indonesia and the U.S. all exploited these gaps. Defenses now hinge on depth sensing, micro-movement analysis, rPPG signals and tamper-proof pipelines. On the enterprise side, Microsoft released patches for two Windows zero-days—GreenPlasma (CVE-2026-45586) and a regressed MiniPlasma bug—and shared mitigations for a BitLocker bypass. But other high-severity flaws like RedSun and BlueHammer are still unpatched. Meanwhile, Intune Administrator roles remain dangerously underprotected: a single compromised Graph API registration can lead to mass device wipes. Treat them like Domain Admins—just-in-time activation, phishing-resistant MFA and tight RBAC.
Questions about this article
No questions yet.