Threat Brief — 2026-09-14 — Flowise RCE and Trusted-Device Eavesdropping
Today's feed is light on fresh critical vulnerabilities but surfaces two notable technique developments worth attention: a practical demonstration of how Flowise AI's config-execution model turns admin-panel access into remote command execution, and a report that law enforcement can read end-to-end encrypted messages by registering a victim's machine as a trusted device — without breaking encryption. A malicious Twitch browser extension leaking OAuth tokens from roughly 31,000 users remains active and carries a usable IoC.
Top items
- GitLab CVE-2026-85706KEV — CISA KEV remediation deadline is today. This CVSS 10.0 unauthenticated arbitrary file read via the repository commits API affects GitLab CE/EE versions 18.7–19.1.7, 19.2–19.2.5, and 19.3–19.3.1. It is known to be exploited in the wild and was added to CISA KEV on 2026-09-11; the remediation deadline falls today. This story was first reported 2026-09-12 via CISA KEV. (src: NVD / CISA KEV / BleepingComputer)
- Malicious Twitch extension leaks OAuth tokens from ~31,000 users. The browser extension "Twitch Enhanced Viewer | JeetBot" forwards user Twitch OAuth tokens to proxy servers via an
&auth=query parameter. The IoC domain is jeetbot.cc, operated by Russian commercial bot SaaS JeetBot (developer Aleksandr Popov, Cyprus). This story was first reported today but has not yet been featured in a brief. (src: VirusTotal / The Hacker News)
- Flowise AI admin panel access enables remote command execution. A writeup demonstrates that Flowise — a platform for building AI agents — accepts user-supplied configuration and executes it as JavaScript, meaning access to the admin panel trivially escalates to RCE. This is a relevant pattern for any organisation exposing AI-agent orchestration tools with code-execution backends. (src: Xakep)
- Law enforcement reads Signal, Telegram, and WhatsApp messages without breaking encryption. A report indicates that police can access encrypted messaging content by converting a target's computer into a trusted device for the messaging account, bypassing the need to defeat end-to-end encryption itself. This shifts the threat model from cryptographic attack to endpoint compromise and lawful-access tooling. (src: SecurityLab)
- Unit 42 publishes behavioural clustering model for cloud identity threat detection. A new research post describes mapping cloud identity roles from audit logs using standard SQL queries, enabling continuous detection of anomalous identity behaviour without custom telemetry pipelines. Relevant to defenders building detection logic for cloud environments. (src: Unit 42)
Themes
AI platforms as attack surface. The Flowise writeup and last week's reports of trusted AI platforms being abused to host malware both reinforce that AI-agent orchestration tools with code-execution capabilities are a growing target. Admin-panel access to such platforms should be treated as equivalent to production server access.
Endpoint trust over crypto strength. The trusted-device law-enforcement technique underscores a broader pattern: attackers and investigators increasingly bypass strong encryption by compromising the endpoint or hijacking device-trust relationships rather than attacking the protocol. This is the same class of problem seen in OAuth-token theft and malicious browser extensions like the Twitch/JeetBot case.
