hacker-news · Crawled Sep 1, 2026

Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity

6 IoCs 5 CVEs
Read original article ↗

AI Summary

Threat actors are actively exploiting two critical vulnerabilities, CVE-2026-0768 in Langflow and CVE-2026-66066 (KindaRails2Shell) in Ruby on Rails, to conduct credential probing, remote code execution, and command-and-control activities. Exploitation of CVE-2026-66066 involves uploading a crafted image to read sensitive files, leak environment secrets, and achieve RCE, particularly when libvips is used for image processing. Attackers have targeted canary systems globally, with source traffic traced to Russia and a single IP in France, and C2 infrastructure in Israel. Additional post-exploitation activities include deploying credential harvesters, cryptominers, disabling auditd, and lateral movement.

AI-extracted · verify before operational use

Extracted Entities 5 found

Indicators of Compromise 6 extracted

Type Value Detail
IP France Details →
IP Israel Details →
Domain canary Details →
Filename .sysd Details →
Filename .bash_history Details →
Filename /root/.cache/langflow/secret_key Details →

MITRE ATT&CK TTPs 36 techniques

T1003 OS Credential Dumping · Credential Access T1021 Remote Services · Lateral Movement T1059.001 PowerShell · Execution T1059.003 Windows Command Shell · Execution T1071.001 Web Protocols · Command And Control T1083 File and Directory Discovery · Discovery T1190 Exploit Public-Facing Application · Initial Access T1485 Data Destruction · Impact T1566 Phishing · Initial Access T1027 Obfuscated Files or Information · Defense Evasion T1056.001 Keylogging · Collection T1059 Command and Scripting Interpreter · Execution T1078 Valid Accounts · Defense Evasion T1082 System Information Discovery · Discovery T1098 Account Manipulation · Persistence T1105 Ingress Tool Transfer · Command And Control T1114 Email Collection · Collection T1484 Domain or Tenant Policy Modification · Defense Evasion T1555 Credentials from Password Stores · Credential Access T1570 Lateral Tool Transfer · Lateral Movement T1588 Obtain Capabilities · Resource Development T1053.003 Cron · Execution T1055 Process Injection · Defense Evasion T1059.004 Unix Shell · Execution T1068 Exploitation for Privilege Escalation · Privilege Escalation T1070.001 Clear Windows Event Logs · Defense Evasion T1075 T1075 T1133 External Remote Services · Persistence T1195.001 Compromise Software Dependencies and Development Tools · Initial Access T1210 Exploitation of Remote Services · Lateral Movement T1486 Data Encrypted for Impact · Impact T1490 Inhibit System Recovery · Impact T1499 Endpoint Denial of Service · Impact T1505.003 Web Shell · Persistence T1552 Unsecured Credentials · Credential Access T1619 Cloud Storage Object Discovery · Discovery