<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Langflow on CuraSec</title><link>https://curasec.metacog.co.kr/tags/langflow/</link><description>Recent content in Langflow on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 05 Aug 2026 13:01:27 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/langflow/index.xml" rel="self" type="application/rss+xml"/><item><title>CISA KEV: Langflow RCE, Tomcat, and N-central Actively Exploited</title><link>https://curasec.metacog.co.kr/insights/2026-08-05-cisa-flags-langflow-rce-tomcat-and-n-central-flaws-as-active/</link><pubDate>Wed, 05 Aug 2026 13:01:27 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-05-cisa-flags-langflow-rce-tomcat-and-n-central-flaws-as-active/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> All three CVEs are CISA KEV-listed with confirmed active exploitation; CVE-2026-9198 in Langflow is a CVSS 9.8 unauthenticated RCE with a public PoC — patch Langflow, Apache Tomcat, and N-central to current vendor-recommended versions immediately, prioritizing any internet-exposed instances.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Active exploitation of Langflow (unauthenticated RCE) and Tomcat creates immediate hunt obligations — sweep logs for exploitation attempts against these services since August 5, check for post-exploitation indicators (new processes, outbound connections) on hosts running any of the three products.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> Three simultaneous KEV additions including a critical AI-workflow tool (Langflow) warrant confirming your team&amp;rsquo;s KEV remediation SLA is on track and verifying whether N-central (an RMM platform) is in scope — RMM compromise can enable broad lateral movement across managed endpoints.&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> CVE-2026-9198 — CISA KEV: listed, EPSS 0.02, public PoC on GitHub&lt;/li>
&lt;/ul></description></item><item><title>CISA KEV: Actively exploited Langflow RCE demands urgent patching</title><link>https://curasec.metacog.co.kr/insights/2026-07-22-cisa-orders-urgent-action-on-actively-exploited-langflow-rce/</link><pubDate>Wed, 22 Jul 2026 12:46:13 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-22-cisa-orders-urgent-action-on-actively-exploited-langflow-rce/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> CISA KEV listing confirms active exploitation of this RCE in Langflow, a framework increasingly adopted by AI development teams. Audit all environments for Langflow deployments and patch to the fixed version immediately — days-level urgency, not weeks.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Active exploitation of a Langflow RCE means any instance in your estate should be treated as potentially compromised; initiate an assume-breach sweep of Langflow hosts for post-exploitation artifacts (new processes, outbound connections, credential access) and hunt for inbound exploitation attempts in web/proxy logs since the vulnerability became public.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> Langflow is niche enough that board escalation is unlikely unless your AI engineering teams are actively using it — confirm with engineering whether Langflow is deployed anywhere in the environment and ensure it lands in the emergency patch queue this week.&lt;/li>
&lt;/ul></description></item><item><title>ENCFORGE Ransomware Targets AI Infrastructure via Langflow RCE</title><link>https://curasec.metacog.co.kr/insights/2026-07-21-new-encforge-ransomware-targets-ai-model-files-in-langflow-r/</link><pubDate>Tue, 21 Jul 2026 12:43:35 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-21-new-encforge-ransomware-targets-ai-model-files-in-langflow-r/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> Active exploitation of a Langflow RCE is being used to deploy Go-based ransomware that encrypts model weights, vector indexes, and training data. If you run Langflow, patch or network-isolate it immediately and review Sysdig&amp;rsquo;s full JADEPUFFER report for host-level IOCs to audit your AI infrastructure.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> A named operator (JADEPUFFER) has been caught in a second confirmed intrusion deploying ENCFORGE ransomware via Langflow; pull Sysdig&amp;rsquo;s IOC set and hunt for anomalous Go process execution or bulk file encryption activity on hosts running Langflow or adjacent AI pipeline components.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> ENCFORGE is the first documented ransomware purpose-built to destroy AI model assets rather than generic data, signaling that AI infrastructure is becoming a distinct extortion target worth adding to the risk register ahead of broader AI investment discussions.&lt;/li>
&lt;/ul></description></item><item><title>EncForge Ransomware Targets AI Training Data and Model Files</title><link>https://curasec.metacog.co.kr/insights/2026-07-21-jadepuffer-agentic-attacks-now-target-ai-model-data-with-ran/</link><pubDate>Tue, 21 Jul 2026 12:43:35 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-21-jadepuffer-agentic-attacks-now-target-ai-model-data-with-ran/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> If you run Langflow, vector databases, or store model checkpoints and training datasets, audit whether those assets are covered by offline/immutable backups and restrict write access to AI model storage paths — ransomware operators are now specifically targeting these artifacts.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> EncForge represents a new ransomware class deliberately targeting AI infrastructure assets; no IOCs or ATT&amp;amp;CK mappings are available yet, so file this as context for future detections around ML pipeline directories and vector DB processes.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> AI training datasets and model checkpoints are now explicit ransomware targets — verify that backup and recovery programs extend to these assets, and add AI model data to the next ransomware tabletop scope if not already present.&lt;/li>
&lt;/ul></description></item></channel></rss>