Identity Lifecycle Management Wasn't Built for AI Agents

2026-07-02T13:24:14Z06bdc512904bbc79177699a49bb47a469da3fab1191a6e698696fb4c20ab0bd1
CVE-2026-33017CVE-2026-45659CVE-2026-50548CVE-2026-50549CVE-2026-8037CVE-2026-8451adobeai-agentargo-cdbrowser-ransomware','monero-miner','password-spray','azure-cli'chocopoccitrix-netscalercredential-theftcursorcvss-10fortibleedkemp-loadmasterkuberneteslangflowphishingprompt-injectionransomwareratsharepointsupply-chain

What happened

A large set of active, high-impact threats and vulnerabilities was reported: AI agents are now being used end-to-end to conduct ransomware and data theft (JADEPUFFER), and Langflow RCE (CVE-2026-33017) continues to be weaponized for miners and full intrusions. Credential-theft campaigns (FortiBleed) have been tied to follow-on ransomware groups (INC, Lynx). Multiple high/critical vulnerabilities are in active use or newly disclosed — Microsoft SharePoint RCE (CVE-2026-45659) was added to CISA KEV, Cursor prompt-sandbox escapes (CVE-2026-50548/50549) enable arbitrary local commands, Progress/K?

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
06bdc512904bbc79177699a49bb47a469da3fab1191a6e698696fb4c20ab0bd1
Enrichment time
2026-07-02T13:24:14Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.