New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack
Researchers at Sysdig have linked a second attack on the same Langflow server to JADEPUFFER, the AI-agent-driven operator first documented earlier this…
Researchers at Sysdig have linked a second attack on the same Langflow server to JADEPUFFER, the AI-agent-driven operator first documented earlier this…
A new Go-based botnet named NadMesh has been discovered actively hunting exposed AI services to steal cloud credentials and Kubernetes tokens. First…
Threat actors have been observed attempting to exploit a recently patched critical security flaw in Gitea Docker images, according to Sysdig. The…
Gitea Docker images versions before 1.26.3 are vulnerable to CVE-2026-20896, which allows unauthenticated access via a trusted reverse proxy header. The fix…
CVE-2026-20896 is a critical vulnerability (CVSS 9.8) in Gitea Docker images that allows unauthenticated attackers to bypass authentication by sending a crafted…
An AI-agent-driven operator first documented by Sysdig. Deployed ENCFORGE ransomware against Langflow servers, using Docker socket for host breakout. Previously used throwaway…
Attackers hijacked over 400 packages in the Arch User Repository (AUR) by adopting orphaned projects and modifying build scripts to deploy a…
Docker socket at /var/run/docker.sock was exploited by JADEPUFFER for host breakout, creating privileged containers with host PID namespace and root filesystem mounts.