Threat Brief — 2026-07-22 — AI Tools Turned Against Developers
Executive summary: Two previously reported critical vulnerabilities — Langflow RCE and WordPress wp2shell — are escalating, with CISA now ordering federal agencies to patch Langflow and attackers loading web shells via WordPress flaws. A new actively exploited path traversal in Windmill and a Chrome extension flaw exposing WhatsApp Web conversations demand immediate attention. Meanwhile, a worm disguised as normal AI agent activity is targeting NPM developer infrastructure, and major AI chatbots are being manipulated to recommend malicious GitHub repositories — a troubling convergence of AI and supply-chain risk.
Top items
- CISA orders urgent patching of actively exploited Langflow RCE. Federal agencies are now mandated to prioritise remediation of the Langflow visual AI-agent framework RCE, which has been under active exploitation since at least July 18. JadePuffer ransomware actors have already leveraged this flaw to deploy ENCFORGE ransomware on AI model files. This story was first reported 2026-07-18 by RSS:mandiant-blog (src); CISA's binding directive represents a significant escalation (src: BleepingComputer)
- WordPress wp2shell exploitation escalates to web shells and rogue admin accounts. Attackers are mass-scanning for vulnerable WordPress sites, uploading malicious plugins and web shells, and creating administrative accounts for persistent remote access. This is a continuation of the wp2shell CVE campaign first reported 2026-07-18 by RSS:bleepingcomputer-main (src); the shift from scanning to full web-shell deployment marks a notable operational escalation (src: Xakep)
- Windmill path traversal CVE-2026-29059 under active exploitation. The open-source developer platform Windmill suffers an unauthenticated path traversal (CVSS 7.5) allowing arbitrary server file reads. VulnCheck confirms in-the-wild exploitation. Any deployment exposing Windmill instances to the internet should patch immediately (src: The Hacker News)
- Adobe Acrobat Chrome extension exposed private WhatsApp Web chats. A flaw in the Adobe Acrobat Chrome extension allowed any website to access conversations and data rendered in WhatsApp Web without authentication. Users with the extension installed should update or remove it (src: BleepingComputer)
- KARR Bluetooth car alarm vulnerability enables remote theft of ~2M vehicles. Researchers discovered that the KARR alarm system's Bluetooth proximity feature can be exploited to remotely unlock and steal vehicles within range. An estimated 2 million cars are affected (src: SecurityLab)
- Microsoft ending Exchange 2016/2019 Extended Security Updates in October. Organisations still running Exchange 2016 or 2019 will lose access to security patches after October via the ESU program. Given the history of critical Exchange zero-days, migration planning is now urgent (src: BleepingComputer)
- NPM-targeting worm disguised as normal AI agent activity. CrowdStrike identified a worm that destroys files in infected development systems while masquerading as legitimate AI agent behaviour within NPM infrastructure. The blending of worm-like propagation with AI-agent mimicry complicates detection in CI/CD pipelines (src: SecurityLab)
- AI chatbots (ChatGPT, Gemini, Claude) recommending malicious GitHub repos. Attackers are crafting GitHub repositories with real package names and fake star counts that rank highly enough for major LLMs to recommend them to users asking coding questions. This turns AI coding assistants into unwitting malware distribution vectors (src: SecurityLab)
- South Korean foreign ministry compromised for a full year via training platform. Attackers maintained persistent access to South Korea's MFA systems for approximately 12 months, entering through a continuing-education portal. The prolonged dwell time underscores the risk of overlooking peripheral training and e-learning systems as attack surfaces (src: SecurityLab)
- EU financial institutions leaking customer data via cookie tracking pixels. European banks are inadvertently transmitting customer data to advertising platforms through tracking pixels embedded in their web properties, creating GDPR compliance exposure and potential regulatory action (src: Dark Reading)
Themes
- AI as both weapon and camouflage: Three distinct stories — the NPM worm mimicking AI agent activity, LLMs recommending malicious GitHub repos, and the Langflow AI-framework RCE — illustrate a pattern where AI tooling is simultaneously the attack vector, the delivery mechanism, and the cover. Security teams should assume adversarial use of AI agents is now baseline.
- Exploitation lag shrinking: Langflow and WordPress wp2shell both moved from disclosure to mass exploitation within days. The window between patch availability and active exploitation continues to compress, especially for internet-facing developer and content platforms.
- Peripheral systems as entry points: The South Korean MFA breach via a training portal and the Adobe extension exposing WhatsApp both highlight that non-core systems — e-learning platforms, browser extensions — remain under-secured and highly leveraged by attackers.
===
[{"slug":"jadepuffer-ai-ransomware","headline":"CISA orders federal agencies to patch actively exploited Langflow RCE","findingIds":[4026],"status":"developing","development":"CISA issued binding directive to federal agencies to prioritise Langflow RCE patching; escalation from KEV listing to mandatory remediation order"},{"slug":"wordpress-wp2shell-rce-exploits","headline":"wp2shell exploitation escalates to web shells and rogue admin accounts","findingIds":[4023],"status":"developing","development":"Attackers now deploying web shells, malicious plugins, and creating admin accounts on vulnerable WordPress sites — escalation from earlier mass scanning"},{"slug":"windmill-cve-2026-29059-pat-traversal","headline":"Windmill unauthenticated path traversal under active exploitation","findingIds":[4075],"status":"new","development":""},{"slug":"adobe-acrobat-extension-whatsapp-exposure","headline":"Adobe Acrobat Chrome extension flaw exposed WhatsApp Web chats","findingIds":[4074],"status":"new","development":""},{"slug":"karr-bluetooth-car-alarm-theft","headline":"KARR Bluetooth alarm vulnerability enables remote theft of 2M vehicles","findingIds":[4031],"status":"new","development":""},{"slug":"exchange-2016-2019-esu-ending","headline":"Microsoft ending Exchange 2016/2019 security updates in October","findingIds":[4019],"status":"new","development":""},{"slug":"npm-ai-agent-worm-crowdstrike","headline":"NPM-targeting worm disguised as normal AI agent activity","findingIds":[4028],"status":"new","development":""},{"slug":"llm-github-malware-recommendations","headline":"AI chatbots recommending malicious GitHub repos to users","findingIds":[4021],"status":"new","development":""},{"slug":"south-korea-mfa-training-portal-breach","headline":"South Korean foreign ministry compromised for a year via training platform","findingIds":[4029],"status":"new","development":""},{"slug":"eu-banks-cookie-tracker-data-leak","headline":"EU financial institutions leaking customer data via cookie tracking pixels","findingIds":[4027],"status":"new","development":""}]
