CVE
CVE-2026-34486
Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor
Exploitation IoCs 11
Domain api[.]deepseek[.]com
Domain code[.]newcli[.]com
Domain dashscope[.]aliyuncs[.]com
Filename fofoapi.py
Filename langflow_poc.py
GitHub Repo Chocapikk/CVE-2026-21858
GitHub Repo Hermes Agent
GitHub Repo oscar-mine/CVE-2026-33017
GitHub Repo qassam-315/PAN-OS-User-ID-Buffer-Overflow-PoC
GitHub User KnYuan
GitHub User knaithe
MITRE ATT&CK TTPs 11
T1059 T1059.001 T1071.001 T1078 T1090 T1133 T1190 T1210 T1484 T1566 T1588.001
Command and Scripting Interpreter
Execution
PowerShell
Execution
Web Protocols
Command And Control
Valid Accounts
Defense Evasion
Proxy
Command And Control
External Remote Services
Persistence
Exploit Public-Facing Application
Initial Access
Exploitation of Remote Services
Lateral Movement
Domain or Tenant Policy Modification
Defense Evasion
Phishing
Initial Access
Malware
Resource Development
Source Articles
CISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flaws
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned federal agencies of active exploitation of three critical vulnerabilities in IBM Langflow, N-able N-central, and Apache Tomcat. The Langflow flaw (CVE-2026-9198) allows unauthenticated remote code execution by chaining API endpoints, with proof-of-concept exploits publicly available. A second Langflow vulnerability (CVE-2026-0770) is also being exploited for root-level remote code execution. The N-central vulnerability (CVE-2026-18576) enables attackers to hijack administrative accounts without authentication, despite prior patching attempts. The Apache Tomcat flaw (CVE-2026-34486), stemming from an incomplete fix for a prior encryption issue, is being exploited by a Chinese-speaking threat actor to deploy reverse shells. CISA has added all three CVEs to its Known Exploited Vulnerabilities catalog and mandated mitigation within three days.
bleeping-computer Aug 5, 2026
CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added three vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog due to active exploitation. These include a critical remote code execution flaw in Langflow (CVE-2026-9198), a sensitive data encryption bypass in Apache Tomcat (CVE-2026-34486), and an authentication bypass in N-able N-central (CVE-2026-18556 and CVE-2026-18577). Exploitation of CVE-2026-34486 has been linked to a Chinese-speaking threat actor using the aliases knaithe and KnYuan, who leveraged AI-powered offensive tools like DeepSeek via the Hermes Agent framework to autonomously target internet-exposed systems. The actor combined autonomous reconnaissance with manual exploitation of known vulnerabilities in Citrix NetScaler, Marimo, and IKE VPN, among others, targeting over 460 organizations.
hacker-news Aug 5, 2026
ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories
A Chinese-speaking threat actor operating under the aliases knaithe and KnYuan has launched an AI-powered autonomous hacking campaign leveraging the Hermes Agent framework with DeepSeek as a reasoning engine to exploit seven critical vulnerabilities in Langflow, n8n, Citrix NetScaler, Apache Tomcat, Marimo Notebook, Palo Alto PAN-OS, and Microsoft Windows IKE Extensions. The campaign uses AI models to autonomously conduct vulnerability assessment, target selection, and exploit generation, with command and control coordinated via Telegram. The actor also leverages publicly available AI tools like Claude Code, Codex, and Qwen Code to support operations. When initial exploitation fails, the system automatically searches for new critical CVEs using GitHub PoCs to prioritize attack surfaces.
hacker-news Jul 30, 2026
Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks
Unit 42 identified a Chinese-speaking threat actor operating under the aliases knaithe and KnYuan who conducted an AI-enabled autonomous cyberattack campaign. The actor used the Hermes Agent framework with DeepSeek as the reasoning engine to autonomously enumerate vulnerabilities, acquire exploit code, and launch attacks without human intervention. They targeted multiple vulnerabilities including CVE-2026-33017 in Langflow and chained CVEs in n8n (CVE-2026-21858 and CVE-2025-68613), though exploitation attempts failed due to configuration requirements. Manual operations successfully exploited CVE-2026-3055 in Citrix NetScaler, leading to confirmed data exfiltration. The campaign was exposed when the actor accidentally exposed their infrastructure via an HTTP file server.
unit42 Jul 30, 2026