AI Security
Zammad Zero-Day Vulnerabilities Exploited
Two Zammad zero-day vulnerabilities, CVE-2026-102489 and CVE-2026-102490, let an attacker take over the open-source helpdesk and reach root on its server. The Dutch Institute for Vulnerability Disclosure (DIVD) says an automated AI agent chained them against its own network on September 21. CISA has added the first flaw to its Known Exploited Vulnerabilities catalog, and…
Read MoreSalesforce Agentforce AI Agent Vulnerability
A Salesforce Agentforce AI agent vulnerability, publicly disclosed September 24 by research firm Zenity Labs under the name “SalesBleed,” let an attacker plant a hidden instruction in an ordinary sales lead form and later exfiltrate CRM data with zero clicks, once an employee simply asked their AI agent to look at the newest lead. Salesforce…
Read MoreRuflo RufRoot CVE-2026-59726: AI Agents Hijacked
Ruflo RufRoot CVE-2026-59726, a maximum-severity CVSS 10.0 flaw disclosed by Noma Security, lets an unauthenticated attacker take full control of an AI agent platform used by an estimated one million people — through a single HTTP request against a management bridge that ships exposed to the network by default. What Happened Ruflo is an open-source…
Read MoreLangflow CVE-2026-55255 KEV: AI Agent Flaw Explained
The Langflow CVE-2026-55255 KEV entry, added by CISA on July 7, marks the first time an AI agent orchestration platform has ever appeared in the Known Exploited Vulnerabilities catalog. The flaw carries a CVSS score of just 6.1 from CISA, yet KEVIntel and CIRCL independently score the same bug 9.9, because it lets an authenticated…
Read MoreJADEPUFFER Agentic AI Ransomware Attack
JADEPUFFER agentic AI ransomware is, according to Sysdig’s Threat Research Team, the first publicly documented case of a ransomware attack executed start to finish by an autonomous AI agent — from initial access through a Langflow vulnerability to database encryption and extortion, with no human operator directing any step. What Happened Sysdig identified JADEPUFFER, this…
Read More
