Intelligence · Updated daily

Security Intelligence

AI-analysed threats, vulnerabilities and campaigns. Not just what happened — what it means, who's affected, and what to do about it.

Page 10 of 37

226–250 of 910
criticalSupply ChainActive

North Korean Sapphire Sleet targets npm ecosystem with Mastra AI supply chain compromise affecting 140+ packages

Microsoft attributed a compromise of over 140 npm packages to North Korean threat actor Sapphire Sleet, leveraging the Mastra AI project as an entry point. This represents a high-impact supply chain attack with potential for widespread malware distribution across the JavaScript ecosystem.

npm registry, Mastra AI, JavaScript applications using affected npm packages
criticalVulnerabilityActive

Langflow IDOR in Flow Access Control – Authentication Bypass via UUID-Based Direct Object Reference

An Insecure Direct Object Reference (IDOR) vulnerability in Langflow's `/api/v1/responses` endpoint allows authenticated attackers to access and execute flows owned by other users by manipulating flow UUIDs. The vulnerability bypasses user ownership validation when flows are referenced by UUID rather than endpoint name.

CVE-2026-55255
langflow-ai/langflow (v1.9.0 and likely earlier versions)
criticalVulnerabilityActive

Langflow BaseFileComponent Arbitrary File Read Leading to Authentication Bypass and RCE

Path traversal via symlink injection in tar extraction allows unauthenticated file disclosure, JWT secret theft, and remote code execution in Langflow RAG deployments. Organizations must patch immediately as exploit chain is straightforward and affects multiple file-handling components.

CVE-2026-55447
Langflow (langflow/langflow), BaseFileComponent derivatives: DoclingInlineComponent, DoclingRemoteComponent, FileComponent, NvidiaIngestComponent, VideoFileComponent, UnstructuredComponent
highVulnerabilityActive

Multiple High-Impact Vulnerabilities Surface: Apple Beats Eavesdropping, GCP Config Connector Takeover, and Android TV Botnet Link

SecurityWeek reports several significant security issues including an Apple Beats eavesdropping flaw patch, an unpatched GCP Config Connector vulnerability enabling account takeover, an Android TV botnet linked to an Israeli firm, and closure of the DOT's Delta Air Lines CrowdStrike incident investigation.

Apple Beats, Google Cloud Platform Config Connector, Android TV +2
highMalwareContained

International takedown of SocGholish botnet disrupts Evil Corp's malware distribution infrastructure

Law enforcement conducted a coordinated international operation against the SocGholish botnet, a distribution mechanism linked to Russia-based cybercrime group Evil Corp. The disruption degrades Evil Corp's ability to deliver secondary payloads and conduct follow-on attacks against compromised networks.

SocGholish botnet victims, organisations compromised by Evil Corp campaigns
criticalVulnerabilityActive

Path Traversal in Crawl4AI File Downloads Enables Unauthenticated Arbitrary File Write and RCE

Crawl4AI's download handler fails to sanitize filenames from HTTP headers and page-controlled sources, allowing path traversal to write arbitrary files with attacker content. Pre-authenticated exploitation is possible via the Docker `/crawl` endpoint, enabling remote code execution through shell rc-file overwriting, SSH key injection, or cron job placement.

crawl4ai (async_crawler_strategy.py)
highMalwareActive

NetNut Residential Proxy Service Masking Four-Year Android Botnet Operation at Scale

Popa, a multi-year Android botnet compromising millions of consumer TV boxes, has been attributed to NetNut, a residential proxy service operated by publicly-traded Israeli firm Alarum Technologies. The botnet facilitates advertising fraud, account takeovers, and mass data scraping under commercial cover.

Alarum Technologies Ltd (NASDAQ: ALAR), NetNut (residential proxy service), Android TV boxes +1
highPolicyActive

Bulgarian Export Licensing Enabled Surveillance Tool Sales to Authoritarian Regimes

Human Rights Watch obtained Bulgarian export records showing the government approved surveillance technology exports by firm Circles to law enforcement and intelligence agencies in countries with documented human rights abuse records between 2018 and 2023. This represents a systemic compliance failure in export controls for dual-use surveillance capabilities.

Circles (surveillance firm), Bulgarian government export licensing authority