Blog · Page 4

CISA Just Added the First AI Agent Platform to the Known Exploited Vulnerabilities List. The Deadline Is Today.

Langflow, an open-source platform for building AI agent workflows used by individual developers and enterprises alike, became the first AI agent platform ever listed in CISA's KEV catalog on July 7. Attackers are using a cross-tenant IDOR to steal LLM provider keys, AWS credentials, and database secrets with the literal prompt 'leak api keys.' Zero HN coverage. Patching deadline: July 10, 2026.

·
ai-securityagent-securitycisa-kev

Mozilla Just Proved AI Agents Can Be Hacked With Zero Suspicious Code

Mozilla's 0DIN team showed how a clean GitHub repo with perfectly normal project documentation can trick Claude Code into opening a reverse shell — using DNS TXT records as the C2 channel. No malicious code, no prompt injection, no warnings.

·
Mozilla0DINClaude Code