AI infrastructure / Langflow RCE: 34 minutes to server compromise

After all the coverage this got, we were curious to see how attackers were actually exploiting this in the wild! So we deployed a few production instances with our security platform turned on.

bitbison.io
u/sbahra — 15 hours ago
▲ 12 r/threatintel+3 crossposts

Shai-Hulud rebuilt as a standalone stealer

We found a new Mini Shai-Hulud variant that makes the worm a general Linux post-exploitation payload and continues through with Github and NPM propagation.

bitbison.io
u/sbahra — 8 days ago