logo

Hackers Exploit Critical Langflow and Ruby on Rails Flaws in Active RCE Attacks

ID: 968f9fcc-1c76-5430-9dc3-ec7a3401bba2

STIX ID: report--968f9fcc-1c76-5430-9dc3-ec7a3401bba2

Feed Name: GBHackers

Threat Score
72/100

Date Published: 2026-09-01

Date Updated: 2026-09-11

Author: Divya

...
...

Active exploitation campaigns are targeting an unauthenticated RCE in Langflow (CVE-2026-0768) and a Ruby on Rails Active Storage file read-to-RCE (CVE-2026-66066). Observed activity includes reconnaissance for environment variables and files holding OpenAI and AWS credentials, credential harvesting attempts, and establishment of C2 communications; detections were seen across Canary sensors in multiple countries, prompting urgent mitigation and credential rotation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.