Advertisement
ENCFORGE Ransomware Targets AI Systems via Langflow RCE
New ENCFORGE ransomware, attributed to JADEPUFFER, leverages a Langflow RCE vulnerability to encrypt AI model files, weights, and training data.
CVE-2024-37014: CISA Orders Federal Agencies to Patch Langflow
CISA added CVE-2024-37014, a critical authentication bypass in the Langflow AI framework, to its KEV catalog following reports of active exploitation.
JadePuffer: First LLM-Driven Ransomware Leverages Langflow Flaw
Analysis of JadePuffer, the first reported LLM-driven ransomware, which exploited a Langflow vulnerability to exfiltrate database data and encrypt systems.
Agentic AI Automates Ransomware Attacks via Langflow Exploitation
Agentic AI agents demonstrate automated multi-stage ransomware attacks using Langflow, raising concerns for AI development security and future threat automation.
JADEPUFFER AI Agent Exploits Langflow RCE for Automated Ransomware
The threat actor JADEPUFFER has pioneered the use of AI agents to automate end-to-end ransomware attacks via Langflow RCE, from initial access to data wiping.
CVE-2024-5027: Langflow Path Traversal Exploited in Attacks
Security researchers observe active exploitation of CVE-2024-5027, a high-severity path traversal flaw in the Langflow AI platform allowing arbitrary file writes.
Advertisement
CVE-2025-34291 & CVE-2023-41179: CISA Warns of Active Exploitation
CISA adds Langflow and Trend Micro Apex One vulnerabilities to KEV. Learn how to mitigate CVE-2025-34291 and CVE-2023-41179 to prevent active exploitation.
Langflow AI Platform: Critical Code Injection Under Active Attack
Threat actors are actively exploiting a critical code injection vulnerability in the Langflow AI platform, demanding immediate patching to prevent compromise.
Langflow CVE-2026-33017: AI Workflow Hijacking Under Active Exploitation
CISA warns of active exploitation of CVE-2026-33017 in Langflow, enabling attackers to hijack AI workflows and potentially compromise AI agents.
CVE-2026-33017: Langflow Code Injection - Patch Immediately
CISA adds actively exploited Langflow Code Injection Vulnerability (CVE-2026-33017) to KEV catalog. Critical patch urged for all organizations.
CVE-2026-33017: Critical Langflow RCE Exploited within 20 Hours
CVE-2026-33017 is a critical RCE vulnerability in Langflow currently under active exploitation. Learn how to secure your AI orchestration and detect attacks.