newsמקור: The Hacker News1.9.2026
תוקפים מנצלים פרצות קריטיות ב-Langflow וב-Rails לפריצת נתונים ופעילות C2
Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity

◆ סיכום AI
איומים מנצלים שתי פרצות קריטיות ב-Langflow וב-Ruby on Rails, כולל CVE-2026-0768 המאפשרת ביצוע קוד פייתון שרירותי. פרצה זו עם ציון CVSS של 9.8, נגרמת מחוסר אימות קלט משתמש. הדבר מוביל לפעולות סייבר ממוקדות לאיסוף פרטי גישה ופעילות שליטה ובקרה (C2).
# מהמקור
Threat actors are exploiting two critical flaws impacting Langflow and Ruby on Rails, according to new findings from VulnCheck. The vulnerabilities in question are listed below - CVE-2026-0768 (CVSS score: 9.8) - A lack of proper validation of a user-supplied input vulnerability that could be exploited to execute arbitrary Python code in the context of the root user. CVE-2026-66066 aka
#vulnerability#langflow#ruby-on-rails#cve
קרא במקור