More on the topic...
Generating detailed summary...
Failed to generate summary. Please try again.
Seven thousand Langflow servers are under active attack right now. Hackers are chaining three known bugs—in LangGraph’s SQLite checkpoint poisoner, Langflow’s file-upload flaw, and LangChain-core’s prompt loader—to gain code execution and siphon off API keys. Langflow instances are already spawning cron-based shells on exposed servers. Teams using any of these tools need to patch to the latest versions, lock down defaults, and audit upload endpoints immediately.
Gizmodo got hit when a compromised account injected fake CAPTCHA pop-ups that delivered ClickFix malware. Windows users risked a NetSupport RAT install, while the macOS payload fizzled at a ZIP password prompt. The site was taken down, the malicious script removed, and the account secured. Meanwhile, Apple quietly pushed Beats Firmware Update 1B211 to fix CVE-2025-20701. The flaw in Airoha Bluetooth chips let attackers within range listen through unpaired Beats Studio Buds and even crack pairing keys. The update installs automatically when the buds are in their case near an Apple device—check under Settings > Bluetooth to confirm.
FortiGate devices remain a major problem in the wake of FortiBleed. Attackers scoured the internet, logged in via old backdoors or unpatched holes, exported full configs, then cracked password hashes with rented GPUs. They sold VPN credentials and set up their own admin accounts, SSH and RDP rules, and IPsec tunnels. About a thousand organizations are confirmed hit. Defenders should scan FortiOS logs for config-export events, compare public IPs against FortiBleed lists, rebuild any affected boxes from scratch with MFA on new admin accounts, patch firmware, and rotate all site-to-site keys.
The latest agentjacking exploit targets Sentry. Exposed Sentry DSNs let attackers send a malicious error event that tricks AI coding assistants—Claude Code, Cursor, Codex—into running an injected npx command. Because the agents treat the event as a trusted “fix,” they hand over AWS keys, GitHub tokens and more, bypassing EDR, WAF, IAM, VPN and firewall controls. Every MCP integration now needs runtime-level gating for agent-initiated commands. Treat any front-end credential as if it can turn into full compromise.
Questions about this article
No questions yet.