Brute[verified]@BRuteLogicGeneral
The post describes two CVEs affecting Langflow through an exec() sink, provides search‐based detection steps, but offers no PoC, exploit, patch, or evidence of active exploitation.
spencer[verified]@techspenceActive Exploitation
The post documents a live ransomware attack leveraging CVE‑2025‑3248 against langflow, demonstrating active exploitation resulting in database compromise and data extortion.
Sysdig[verified]@sysdigActive Exploitation
Sysdig TRT reported an agentic ransomware operation that actively exploited CVE-2025‑3248 on an internet‑facing Langflow instance, driving autonomous extortion activities. No patch, PoC, or detailed technical vulnerability information was provided.
White Knight Labs[verified]@WKL_cyberActive Exploitation
CVE-2025-3248 was exploited in a ransomware attack against Langflow, with Sysdig reporting the first agentic operation and quick remediation.
GreyNoise[verified]@GreyNoiseIOActive Exploitation
The text reports that two Langflow RCE flaws (CVE-2025-3248 and CVE-2026-0770) are CISA-known exploited and observed in adversary connection attempts, indicating active exploitation.
White Knight Labs[verified]@WKL_cyberGeneral
The post highlights Sysdig’s documentation of a ransomware operation driven by an LLM agent and references CVE‑2025‑3248 in Langflow with a noted working fix, but offers no proof‑of‑concept, exploit code, or evidence of active exploitation.
theBOZO[verified]@nftsTokiActive Exploitation
The post asserts that JADEPUFFER exploited CVE-2025-3248 in the wild, enabling a fully autonomous ransomware operation without manual script usage.
التميمي[verified]@altmemy199Active Exploitation
Researchers report an active AI‑driven ransomware campaign, JADEPUFFER, that exploited CVE‑2025‑3248 in Langflow to steal cloud keys, encrypt data, and demand ransom, with no recovery key available.