1 link tagged with all of: vulnerabilities + breaches + firmware
Click any tag below to further narrow down your results
Links
This issue covers fresh attacks on AI agent infrastructure—over 7,000 Langflow servers hit via chained bugs in LangGraph and LangChain—and a new agentjacking risk where exposed Sentry keys let attackers hijack Claude-based workflows. It also details Apple’s Beats Studio Buds wiretap patch, Gizmodo’s ClickFix malware incident, and ongoing FortiBleed fallout, plus guidance on client-side bot detection, post-quantum crypto, and microVM limits.
- 7,000+ Langflow servers are being actively compromised by chaining three known bugs across LangGraph, Langflow, and LangChain-core, giving attackers code execution and API key theft.
- A new "agentjacking" technique abuses exposed Sentry DSNs to inject fake error events that trick AI coding agents (Claude Code, Cursor, Codex) into running malicious commands and leaking AWS/GitHub credentials, bypassing traditional security controls entirely.
- Apple's Beats Studio Buds firmware fix (CVE-2025-20701) patches an Airoha Bluetooth chip flaw that let nearby attackers eavesdrop through unpaired earbuds and crack pairing keys.
- Roughly 1,000 organizations have been confirmed breached via FortiBleed, with attackers exporting configs, cracking password hashes via rented GPUs, and planting persistent backdoors (new admin accounts, SSH/RDP rules, IPsec tunnels).