Skip to main content
Security AI

Langflow flaw is being exploited to harvest cloud and AI credentials

Langflow flaw is being exploited to harvest cloud and AI credentials Image: Primary
Threat actors are exploiting CVE-2026-0768, an unauthenticated remote-code-execution flaw in Langflow's custom-component code validator, to steal credentials, tokens and keys, according to VulnCheck observations reported by BleepingComputer. The critical issue affects Langflow 1.4.2 and earlier and can execute arbitrary code with root privileges. VulnCheck observed 360 attacks as of September 1, including attempts to collect OpenAI API keys, AWS secrets and Langflow administrative credentials.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from BleepingComputer and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
AI Products
AI Products

Lambda reportedly raises $1 billion in private debt for Nvidia GPUs

Cloud provider Lambda has reportedly secured $1 billion in short-term private debt to buy Nvidia GPUs, according to Bloomberg reporting cited by Data Center Dynamics. The company is expected to lease the chips to Microsoft under t...

AI
AI

AWS makes Claude Fable 5.1 available through Bedrock

AWS said Claude Fable 5.1 is available today through Amazon Bedrock and Claude Platform on AWS, including US Geo and Global inference profiles. AWS describes the model as suited to coding, scientific research and enterprise workfl...

Capital
Capital

HiBob funding round values HR software company above $3.2 billion

Salesforce is investing in HR software company HiBob in a $160 million funding round that values the startup at more than $3.2 billion, according to people familiar with the matter. The investment gives HiBob new capital alongside...

AI Security
AI Security

OpenAI says Astra reached its critical cyber-capability threshold

OpenAI says its forthcoming Astra model has reached the company's threshold for critical cyber capabilities, defined as independently finding and exploiting previously unknown vulnerabilities in real-world software. The company p...

AI
AI

Anthropic releases Fable 5.1 with lower cache-read pricing

Anthropic introduced Claude Fable 5.1, which it says is generally available, alongside the more restricted Claude Mythos 5.1. Anthropic says Fable 5.1 will cost an estimated 25% less than Fable 5 for typical token-billed workloads...