Security News

Cybersecurity news aggregator

CRITICAL Attacks SC Media

Critical Langflow vulnerability exploited to deploy Monero cryptocurrency miner

Threat actors are exploiting CVE-2026-33017, a critical (CVSS 9.3) unauthenticated remote code execution vulnerability in Langflow, via its API endpoints to deploy a Monero miner. The attack uses a single line of Python code to download a script that installs a Go-based miner, which terminates competing miners, disables multiple security controls, and establishes persistence via cron jobs.
Read Full Article →

Malware Critical Langflow vulnerability exploited to deploy Monero cryptocurrency miner July 2, 2026 Share By SC Staff (Adobe Stock) Threat actors are actively exploiting a critical vulnerability in Langflow, identified as CVE-2026-33017, to deploy a Monero cryptocurrency miner, according to Trend Micro. This vulnerability, with a CVSS score of 9.3, allows for unauthenticated remote code execution, enabling attackers to gain initial access to enterprise networks by targeting exposed artificial intelligence application endpoints. The exploitation campaign was observed between March 27 and April 15, 2026, with further coverage provided by The Hacker News. The attack chain begins with a single line of Python code executed via an unauthenticated Langflow API endpoint. This code downloads a shell script that fetches and launches a cryptocurrency miner binary as a detached process. The malware is designed to terminate competing miners from groups like Kinsing and WatchDog, remove rival wallet data, disable security controls, and establish persistence through cron jobs. It also spreads to other systems via reused SSH keys. The miner binary, written in Go, disables security measures such as AppArmor, UFW, iptables, SELinux, and cloud security agents. It also removes system logs and manipulates file attributes to maintain its presence. The campaign highlights how exposed AI application endpoints are becoming a new entry point for threat actors. Source: The Hacker News SC Staff Related Malware Malicious browser extension targets cryptocurrency users with wallet address swapping SC Staff July 1, 2026 The "Google Notes" extension, identified by McAfee researchers, operates by requesting broad permissions, including access to all websites, browsing history, and the clipboard, which are unusual for a note-taking application. Malware Ousaban banking trojan targets Spain and Portugal with new stealth techniques SC Staff July 1, 2026 The Ousaban campaign begins with a phishing PDF disguised as a corrupted file, prompting users to click an "Update" button. Malware ScreenConnect abused to deploy AsyncRAT in widespread campaign SC Staff July 1, 2026 This activity is part of a large, multi-language campaign that distributes malicious installer archives hosted on spoofed websites, according to a recent report by The Hacker News. Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Adware You can skip this ad in 5 seconds

Share this article