New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack
Researchers at Sysdig have linked a second attack on the same Langflow server to JADEPUFFER, the AI-agent-driven operator first documented earlier this…
Researchers at Sysdig have linked a second attack on the same Langflow server to JADEPUFFER, the AI-agent-driven operator first documented earlier this…
A new Go-based botnet named NadMesh has been discovered actively hunting exposed AI services to steal cloud credentials and Kubernetes tokens. First…
Threat actors have been observed attempting to exploit a recently patched critical security flaw in Gitea Docker images, according to Sysdig. The…
Gitea Docker images versions before 1.26.3 are vulnerable to CVE-2026-20896, which allows unauthenticated access via a trusted reverse proxy header. The fix…
A critical reverse-proxy authentication bypass in Gitea Docker images, patched in June 2026. Threat actors were observed probing the flaw 13 days…
An AI-agent-driven operator first documented by Sysdig. Deployed ENCFORGE ransomware against Langflow servers, using Docker socket for host breakout. Previously used throwaway…
Attackers hijacked over 400 packages in the Arch User Repository (AUR) by adopting orphaned projects and modifying build scripts to deploy a…
Docker socket at /var/run/docker.sock was exploited by JADEPUFFER for host breakout, creating privileged containers with host PID namespace and root filesystem mounts.