Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity
The Hacker News
Read full postSecurity researchers at VulnCheck report active exploitation of two critical vulnerabilities in Langflow and Ruby on Rails, enabling attackers to execute arbitrary code and harvest credentials. Exploits have surged since August 30, 2026, with attacks primarily originating from Russia targeting UK systems. These attacks involve reconnaissance, credential theft, and deploying malware such as Python harvesters and cryptocurrency miners.




