If You Run Langflow Or OpenVSwitch You Need To Act Today

August 5
4 mins

Episode Description

Here is your briefing for Wednesday, August 5, 2026. The U.S. Cybersecurity and Infrastructure Security Agency added three flaws to its Known Exploited Vulnerabilities catalog on August 5, citing evidence of active exploitation in the wild. CVE-2026-9198 is a code injection vulnerability in Langflow that allows unauthenticated attackers to achieve full remote code execution on default deployments. It was fixed in July with version 1.10.1. CVE-2026-34486 is a missing encryption of sensitive data flaw in Apache Tomcat that allows a bypass of EncryptInterceptor. Fixed in April. CVE-2026-18556 is an authentication bypass in N-able N-central. An incomplete fix for the N-central issue prompted the addition. These are not theoretical. Attackers are already using them. CISA's move is a reminder that the window between disclosure and exploitation keeps shrinking. Langflow in particular is popular in AI and data pipeline environments. If you're running it exposed, you're already late.  A memory corruption flaw in the Linux kernel's Open vSwitch datapath gives ordinary local users a path to root on a broad set of default-configured distributions. A public exploit ships with pre-built records for roughly 800 kernel builds. The vulnerability, tracked as CVE-2026-64531 with a CVSS score of 7.8, was disclosed by researcher Asim Manizada on July 28. The bug sits in the kernel datapath, not the userspace daemon. An attacker needs no existing OVS bridge, no running ovs-vswitchd, and no host-level CAP_NET_ADMIN. On affected systems where the OVS kernel datapath is available and unprivileged user namespaces are enabled, an ordinary user can create private namespaces with unshare, gain the capability inside that namespace, and reach the vulnerable flow-installation path. This is a local privilege escalation with a working public exploit and broad hardware coverage. If your fleet runs Open vSwitch — and many do for container networking — this one needs attention now. Kali365 is turning a legitimate Microsoft login into a gateway to corporate data. The phishing kit targets US organizations with attacker-controlled device codes that victims approve on Microsoft's real authentication page. Once access and refresh tokens are issued, attackers may retain access to email, documents, and cloud resources. ANY.RUN telemetry records more than 80 public sessions linked to the campaign each week, with the United States as the main target. The kit uses SharePoint-themed lures and other enterprise-looking pages to draw victims into the device code flow. This is device code phishing at scale, and it's working. CrowdStrike's recent threat hunting report noted a 1,500% increase in device code phishing in the first half of 2026 alongside a doubling of vishing. The technique bypasses many traditional controls because the victim is actively approving the request on Microsoft's own infrastructure. If your org still relies on device code flows without additional verification, you're exposed. A cluster of 77 extensions on the Open VSX marketplace has been found to impersonate legitimate developer tools while transmitting information about the systems and development environments on which they were installed. The packages were uploaded between July 26 and August 1 and removed as of August 3. In most cases the extensions send little more than the machine's hostname. In nineteen of them they send a detailed description of the machine, the repository open in the editor, and the CI system the editor is running inside. Fifty-eight were lightweight reconnaissance tools. The rest were more aggressive payloads. This is supply chain compromise at the editor level. Developers install these things thinking they're getting a useful utility. Instead they're phoning home with exactly the kind of context an attacker needs for targeted follow-on operations. The fact that it took a third-party security firm to catch this, rather than

Support the show

See all episodes