AISecHub[verified]@AISecHubActive Exploitation
The digest highlights newly disclosed critical vulnerabilities—particularly CISA’s KEV listing for Langflow—indicating real‑world exploitation, while also providing PoC links and technical details for other CVEs.
WhiskeyHacker[verified]@whiskeyhackerPatch
CISA added CVE-2025-34291 to its KEV list with a June 4 federal patch deadline, but no PoC, exploit, or detailed technical data is provided.
Ahmad Sadeddin[verified]@asadeddinDisclosure
The post highlights three recent vulnerability research articles: an iOS exploit kit, an RCE in Langflow via CORS/refresh-token leakage, and a Linux ptrace race that leaks privileged file descriptors.
CloudSecurityAlliance[verified]@cloudsaActive Exploitation
The briefing states that Langflow’s CVE-2025-34291 has entered the CISA KEV list, indicating it is actively exploited, and urges auditors to review related AI orchestration platforms.
Adam[verified]@seoscottsdaleActive Exploitation
The thread reports that Ghost CMS CVE‑2026‑26980 is being actively exploited on 700+ sites via critical SQL injection, and stresses immediate patching along with broader supply‑chain hygiene.
ThaiCERT By NCSA[verified]@ThaiCERTByNCSAActive Exploitation
The advisory confirms CVE‑2025‑34291 in Langflow is actively exploited, outlines severe technical details, and urges immediate patching and mitigation.
Proficio[verified]@proficioincActive Exploitation
The article reports that CVE-2026-34926 and CVE-2025-34291 have been cataloged by U.S. CISA as known exploited vulnerabilities, indicating real‑world exploitation activity.
piyokango[verified]@piyokangoActive Exploitation
The text announces that CVE‑2025‑34291 has been added to CISA’s KEV catalog, provides the technical details of the flaw, notes that a partial PoC is publicly available, and confirms that active exploitation has been observed by CrowdSec.