Identity Lifecycle Management Wasn't Built for AI Agents
2026-07-02T13:24:14Z•06bdc512904bbc79177699a49bb47a469da3fab1191a6e698696fb4c20ab0bd1
CVE-2026-33017CVE-2026-45659CVE-2026-50548CVE-2026-50549CVE-2026-8037CVE-2026-8451adobeai-agentargo-cdbrowser-ransomware','monero-miner','password-spray','azure-cli'chocopoccitrix-netscalercredential-theftcursorcvss-10fortibleedkemp-loadmasterkuberneteslangflowphishingprompt-injectionransomwareratsharepointsupply-chain
What happened
A large set of active, high-impact threats and vulnerabilities was reported: AI agents are now being used end-to-end to conduct ransomware and data theft (JADEPUFFER), and Langflow RCE (CVE-2026-33017) continues to be weaponized for miners and full intrusions. Credential-theft campaigns (FortiBleed) have been tied to follow-on ransomware groups (INC, Lynx). Multiple high/critical vulnerabilities are in active use or newly disclosed — Microsoft SharePoint RCE (CVE-2026-45659) was added to CISA KEV, Cursor prompt-sandbox escapes (CVE-2026-50548/50549) enable arbitrary local commands, Progress/K?
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 06bdc512904bbc79177699a49bb47a469da3fab1191a6e698696fb4c20ab0bd1
- Enrichment time
- 2026-07-02T13:24:14Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.