bleeping-computer · Crawled Sep 1, 2026
Critical Langflow flaw exploited to steal OpenAI and AWS keys
6 CVEs
Read original article ↗
AI Summary
Threat actors are actively exploiting a critical unauthenticated remote code execution vulnerability, CVE-2026-0768, in Langflow, an open-source AI application framework, to steal sensitive credentials including OpenAI and AWS API keys. The flaw exists in the code validator of Langflow's custom component editor, allowing arbitrary Python code execution with root privileges. Attack activity has been observed on honeypots, primarily originating from Russia, with over 360 exploitation attempts detected. Attackers query environment variables and sensitive files to harvest credentials and maintain persistence.
AI-extracted · verify before operational use
Extracted Entities 6 found
MITRE ATT&CK TTPs 38 techniques
T1003 OS Credential Dumping · Credential Access T1021 Remote Services · Lateral Movement T1059.001 PowerShell · Execution T1059.003 Windows Command Shell · Execution T1071.001 Web Protocols · Command And Control T1083 File and Directory Discovery · Discovery T1190 Exploit Public-Facing Application · Initial Access T1485 Data Destruction · Impact T1566 Phishing · Initial Access T1027 Obfuscated Files or Information · Defense Evasion T1046 Network Service Discovery · Discovery T1055 Process Injection · Defense Evasion T1059 Command and Scripting Interpreter · Execution T1059.004 Unix Shell · Execution T1068 Exploitation for Privilege Escalation · Privilege Escalation T1078 Valid Accounts · Defense Evasion T1082 System Information Discovery · Discovery T1090 Proxy · Command And Control T1105 Ingress Tool Transfer · Command And Control T1133 External Remote Services · Persistence T1195.001 Compromise Software Dependencies and Development Tools · Initial Access T1203 Exploitation for Client Execution · Execution T1210 Exploitation of Remote Services · Lateral Movement T1486 Data Encrypted for Impact · Impact T1499 Endpoint Denial of Service · Impact T1505.003 Web Shell · Persistence T1552 Unsecured Credentials · Credential Access T1583 Acquire Infrastructure · Resource Development T1584 Compromise Infrastructure · Resource Development T1585 Establish Accounts · Resource Development T1586 Compromise Accounts · Resource Development T1587 Develop Capabilities · Resource Development T1588 Obtain Capabilities · Resource Development T1588.001 Malware · Resource Development T1619 Cloud Storage Object Discovery · Discovery T1070.004 File Deletion · Defense Evasion T1135 Network Share Discovery · Discovery T1484 Domain or Tenant Policy Modification · Defense Evasion