1 link tagged with all of: ai-security + vulnerabilities + firmware + infosec + breaches
Links
This issue covers fresh attacks on AI agent infrastructure—over 7,000 Langflow servers hit via chained bugs in LangGraph and LangChain—and a new agentjacking risk where exposed Sentry keys let attackers hijack Claude-based workflows. It also details Apple’s Beats Studio Buds wiretap patch, Gizmodo’s ClickFix malware incident, and ongoing FortiBleed fallout, plus guidance on client-side bot detection, post-quantum crypto, and microVM limits.
- 7,000+ Langflow servers are being actively compromised by chaining three known bugs across LangGraph, Langflow, and LangChain-core, giving attackers code execution and API key theft.
- A new "agentjacking" technique abuses exposed Sentry DSNs to inject fake error events that trick AI coding agents (Claude Code, Cursor, Codex) into running malicious commands and leaking AWS/GitHub credentials, bypassing traditional security controls entirely.
- Apple's Beats Studio Buds firmware fix (CVE-2025-20701) patches an Airoha Bluetooth chip flaw that let nearby attackers eavesdrop through unpaired earbuds and crack pairing keys.
- Roughly 1,000 organizations have been confirmed breached via FortiBleed, with attackers exporting configs, cracking password hashes via rented GPUs, and planting persistent backdoors (new admin accounts, SSH/RDP rules, IPsec tunnels).
infosec
vulnerabilities
ai-security
breaches
firmware