Critical Langflow flaw exploited to steal OpenAI and AWS keys
2026-09-01T19:23:19Z•fd47789007c392d924a9117a3b624326136795b2f3a10d58262bfdcf64a1ec04
CVE-2026-0768ATM jackpottingAWS keysBGP hijackingCisco routersClickFixLangflowMicrosoft ExchangeOpenAI keysPaperCutPowerShellRhysidaTerminalFixVirtualizoractive exploitationcloud service outagecredential theftcryptocurrency exploitdata breachransomwareremote code executionreverse tunnelssupply-chain attackzero-day
What happened
BleepingComputer security feed reporting active exploitation of a critical unauthenticated remote code execution flaw in Langflow (CVE-2026-0768) to steal OpenAI and AWS credentials, alongside additional incidents involving malicious software updates, exposed and exploited vulnerabilities, ransomware, network compromise, credential theft, and financial attacks.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- fd47789007c392d924a9117a3b624326136795b2f3a10d58262bfdcf64a1ec04
- Enrichment time
- 2026-09-01T19:23:19Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.