This day 02:07 06:07 10:07 14:04 18:05 22:05
Info  2026-07-22 14:04Z · last 4h · 18 findings · glm-5.2:cloud

Threat Brief — 2026-07-22 — AI Tools Turned Against Developers

Executive summary: Two previously reported critical vulnerabilities — Langflow RCE and WordPress wp2shell — are escalating, with CISA now ordering federal agencies to patch Langflow and attackers loading web shells via WordPress flaws. A new actively exploited path traversal in Windmill and a Chrome extension flaw exposing WhatsApp Web conversations demand immediate attention. Meanwhile, a worm disguised as normal AI agent activity is targeting NPM developer infrastructure, and major AI chatbots are being manipulated to recommend malicious GitHub repositories — a troubling convergence of AI and supply-chain risk.

Top items

Themes

===

[{"slug":"jadepuffer-ai-ransomware","headline":"CISA orders federal agencies to patch actively exploited Langflow RCE","findingIds":[4026],"status":"developing","development":"CISA issued binding directive to federal agencies to prioritise Langflow RCE patching; escalation from KEV listing to mandatory remediation order"},{"slug":"wordpress-wp2shell-rce-exploits","headline":"wp2shell exploitation escalates to web shells and rogue admin accounts","findingIds":[4023],"status":"developing","development":"Attackers now deploying web shells, malicious plugins, and creating admin accounts on vulnerable WordPress sites — escalation from earlier mass scanning"},{"slug":"windmill-cve-2026-29059-pat-traversal","headline":"Windmill unauthenticated path traversal under active exploitation","findingIds":[4075],"status":"new","development":""},{"slug":"adobe-acrobat-extension-whatsapp-exposure","headline":"Adobe Acrobat Chrome extension flaw exposed WhatsApp Web chats","findingIds":[4074],"status":"new","development":""},{"slug":"karr-bluetooth-car-alarm-theft","headline":"KARR Bluetooth alarm vulnerability enables remote theft of 2M vehicles","findingIds":[4031],"status":"new","development":""},{"slug":"exchange-2016-2019-esu-ending","headline":"Microsoft ending Exchange 2016/2019 security updates in October","findingIds":[4019],"status":"new","development":""},{"slug":"npm-ai-agent-worm-crowdstrike","headline":"NPM-targeting worm disguised as normal AI agent activity","findingIds":[4028],"status":"new","development":""},{"slug":"llm-github-malware-recommendations","headline":"AI chatbots recommending malicious GitHub repos to users","findingIds":[4021],"status":"new","development":""},{"slug":"south-korea-mfa-training-portal-breach","headline":"South Korean foreign ministry compromised for a year via training platform","findingIds":[4029],"status":"new","development":""},{"slug":"eu-banks-cookie-tracker-data-leak","headline":"EU financial institutions leaking customer data via cookie tracking pixels","findingIds":[4027],"status":"new","development":""}]

Public exploits · latest from the exploit feed

ArcadeDB < 26.7.2 Cross-Database Authorization Bypass (IDOR) 2026-08-02 15:45Z · RSS:cxsecurity-wlb Linux Kernel 7.0-7.0.8 & 7.0-rc-7.0-rc7 - Use After Free Exploit 2026-08-02 15:45Z · RSS:cxsecurity-wlb MODX.3.2.1 TLS cookie without secure flag set - COOKIE PHPSESSID HIJACK 2026-08-02 15:45Z · RSS:cxsecurity-wlb Linux Kernel 7.0 DRM UAF LPE Exploit published for CVE-2026-46215 CVE-2026-46215 2026-07-22 14:05Z · CXSecurity / Exploit-DB (RSS) ZTE ZXHN H188A V6 Authentication Bypass 2026-07-22 13:28Z · RSS:cxsecurity-wlb OpenEMR 7.0.2 Arbitrary File Read 2026-07-22 13:28Z · RSS:cxsecurity-wlb PHP Link Directory (phpLD) 2.1.3 - SQL Injection, IDOR, CSRF 2026-07-22 13:28Z · RSS:cxsecurity-wlb KNX visualisering - Broken Access Control 2026-07-22 13:28Z · RSS:cxsecurity-wlb D-Link DSL2600U rom-0 Admin Password Disclosure 2026-07-22 13:28Z · RSS:cxsecurity-wlb Windows Defender (MsMpEng.exe) Race Condition -> LPE / SYSTEM / Use-After-Free -> Crash 2026-07-22 13:28Z · RSS:cxsecurity-wlb