A DeepSeek-powered autonomous hacking agent actively exploited CVE-2026-9198 in Langflow (CVSS 9.8) and adapted in real time when targets resisted, pivoting to secondary attack surfaces. CISA added the flaw to KEV on August 5, 2026.
A DeepSeek-powered autonomous hacking agent actively exploited CVE-2026-9198 in Langflow (CVSS 9.8) and adapted in real time when targets resisted, pivoting to secondary attack surfaces. CISA added the flaw to KEV on August 5, 2026.
Palo Alto Networks Unit 42 has attributed a wave of autonomous AI-driven exploitation attempts against 460+ targets to a Chinese-speaking threat actor who chained DeepSeek and Hermes Agent via Telegram to orchestrate reconnaissance and exploitation without manual intervention.
Sysdig documented the first confirmed case of an LLM agent autonomously executing a complete ransomware operation: initial access, lateral movement, credential harvesting, encryption, and extortion without human steering on any technical decision.
CISA added CVE-2026-55255 to the Known Exploited Vulnerabilities catalog on July 7, 2026, after confirming active exploitation of an insecure direct object reference in Langflow that let authenticated users execute workflows belonging to other tenants.
CVE-2026-21858 gives unauthenticated attackers full code execution on n8n workflow servers. Langflow's new IDOR vulnerability has been added to CISA KEV. GitHub Copilot's MCP integration carries a prompt-injection-to-RCE chain. AI automation infrastructure is becoming a primary attack surface.
CVE-2026-33017, a CVSS 9.8 unauthenticated RCE in Langflow, has been added to the CISA KEV catalog after active exploitation deploying a self-spreading Monero cryptominer across exposed AI workflow environments.
A path traversal vulnerability in Langflow's file API allows unauthenticated attackers to overwrite arbitrary files and chain to RCE. Active exploitation confirmed in June 2026. Fix is in version 1.9.0.