1 link tagged with all of: ai-security + breach + vulnerabilities + infosec-news + threat-intel
Links
This digest covers new exploits in AI and enterprise platforms, including a path traversal flaw in Langflow, a ServiceNow tenant data leak, and critical Ivanti Sentry root bugs. It also highlights Anthropic’s ATT&CK mapping of AI-driven threats and evolving deepfake tactics for bypassing facial recognition.
- Langflow's unauthenticated file upload endpoint is under active exploitation, enabling remote code execution—patch or lock down auth immediately.
- Ivanti Sentry 9.9/10.0 has critical unauthenticated root/admin-creation bugs via a Tomcat API—upgrade to 10.5.2/10.6.2/10.7.1 now.
- Anthropic's ATT&CK mapping of 832 banned accounts found top-tier threat actors chaining fully autonomous multi-step attacks (recon, SSRF, SSH key theft, lateral movement) with no human prompting.
- Deepfake fraud rings (North Korean IT workers, a $38.4M Vietnamese laundering gang, and others) are defeating liveness checks by combining masks, injected video, and real-time deepfakes.
vulnerabilities
ai-security
breach
threat-intel
infosec-news