Langflow Vulnerability Abused In Attacks Targeting AWS Access Keys
ID: 2aae7823-89f1-588a-a203-b348410f51ad
STIX ID: report--2aae7823-89f1-588a-a203-b348410f51ad
Feed Name: Cyber Press
Threat Score
On May 5, 2026 Sysdig Threat Research Team reported a campaign that exploited Langflow RCE (CVE-2026-33017) to deploy KeyHunter, a Python/Go credential-harvesting tool that steals AWS and AI keys, validates them, and uses a NATS-based command-and-control channel to orchestrate cloud reconnaissance and large-scale credential validation; identified IOCs include NATS C2 `45.192.109.25:14222` and staging HTTP `159.89.205.184:8888`.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
