Fetching from the wire…
Top 5 · 2026-04-03 · source-backed
Cisco Talos uncovered "UAT-10608", a credential harvesting campaign exploiting CVE-2025-55182 (CVSS 10.0) in React Server Components and Next.js App Router. 766 servers worldwide. 24 hours. Post-compromise, 91.5% of hosts leaked database credentials and 78.2% exposed SSH private keys.
The attackers built a platform called "NEXUS Listener" with a web GUI. They're not manually exploiting these servers. They built a product for it.
This is the part that caught me off guard. The industrialization. Someone built a management console for mass exploitation of a single vulnerability. The economics of attacks have shifted the same way the economics of software have: build a platform, scale horizontally, automate everything.
Next.js is everywhere in the AI ecosystem. Agent dashboards, internal tools, startup MVPs, production apps. If you're running Next.js App Router, patch immediately. Not "this week." Today. The automated scanning means you're not competing against a human attacker's schedule. You're competing against a bot that never sleeps.
This drops in the same week as Chrome's fourth zero-day of 2026 (CVE-2026-5281, a use-after-free in Dawn WebGPU, CISA federal patch deadline April 15) and the Langflow CVE-2026-33017 active exploitation timeline that Sysdig documented going from disclosure to compromise in 20 hours. Three of Chrome's four 2026 zero-days target graphics/rendering subsystems. The attack surface is shifting toward the rendering pipeline, the AI pipeline, and the frontend framework layer, all at once.
Update Chrome to 146.0.7680.178. Patch Next.js. Audit your Langflow instances. The window between disclosure and mass exploitation is now measured in hours, not weeks.
Each link below shares sources, entities, or timing with this story.
Two AI toolchain CVEs hit CISA's Known Exploited Vulnerabilities catalog this week, and the attack chain connecting them is the kind of thing that should change how you think about supply chain trust. CVE-2026-33017: Langflow, the popular agent workflow builder, has an unauthe...
CVE-2026-33017 is an unauthenticated RCE (CVSS ~9.8) in Langflow's public flow-build endpoint. Attackers weaponized it within 20 hours of disclosure, before any public PoC, by reverse-engineering the advisory text. Exploitation systematically exfiltrated OpenAI, Anthropic, and...
A critical Langflow flaw allows arbitrary Python code execution on any exposed instance with a single unauthenticated HTTP request. Sysdig observed active exploitation within 20 hours of the advisory — before any public exploit code existed. With 145K+ GitHub stars and many in...
OX Security disclosed a systemic vulnerability on June 16 in core Model Context Protocol implementations that enables arbitrary command execution, exposing API keys, internal databases, and chat histories on any vulnerable MCP host. This isn't one bad server. It's a protocol-l...
CVE-2026-44338 (CVSS 7.3) comes from PraisonAI's legacy Flask api_server.py shipping with AUTH_ENABLED=False and AUTH_TOKEN=None, exposing GET /agents and POST /chat to anyone on the network. Sysdig watched a scanner identifying as "CVE-Detector/1.0" hit the exact endpoint und...
Palo Alto Unit 42 disclosed a CVSS 8.8 vulnerability in Chrome's built-in Gemini panel that demonstrates a fundamentally new attack surface. A malicious extension using only basic ad-blocker-level permissions (declarativeNetRequests API) could inject JavaScript into the privil...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.