Critical Langflow flaw exploited to steal OpenAI and AWS keys

2026-09-01T19:23:19Zfd47789007c392d924a9117a3b624326136795b2f3a10d58262bfdcf64a1ec04
CVE-2026-0768ATM jackpottingAWS keysBGP hijackingCisco routersClickFixLangflowMicrosoft ExchangeOpenAI keysPaperCutPowerShellRhysidaTerminalFixVirtualizoractive exploitationcloud service outagecredential theftcryptocurrency exploitdata breachransomwareremote code executionreverse tunnelssupply-chain attackzero-day

What happened

BleepingComputer security feed reporting active exploitation of a critical unauthenticated remote code execution flaw in Langflow (CVE-2026-0768) to steal OpenAI and AWS credentials, alongside additional incidents involving malicious software updates, exposed and exploited vulnerabilities, ransomware, network compromise, credential theft, and financial attacks.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
fd47789007c392d924a9117a3b624326136795b2f3a10d58262bfdcf64a1ec04
Enrichment time
2026-09-01T19:23:19Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.