Sysdig says an LLM-driven operator it calls JADEPUFFER ran a database-extortion campaign on its own, entering through unpatched Langflow flaw CVE-2025-3248. It calls the operation the first documented ransomware run end to end by a model.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+25
- Incentives70
- Confidence50
Microsoft says Storm-3168, also tracked as JADEPUFFER, used two stolen Azure service principals to try deleting more than 100 storage accounts. The deletions took about seven minutes, so the 17 hours of API reads before them were when anyone watching those identities had time to act.
Perspective Coverage
6 publishers
- Builder
- Builder 23%
- Operator
- Operator 70%
- Investor
- Investor 7%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+25
- Incentives55
- Confidence70
Google's threat intelligence group counts 18 exploited flaws a month in 2026, up from 10.5 in 2025, while zero-days rose only from eight to 11. GTIG attributes most of the added attacks to fast weaponization of disclosed n-days, so the exposure sits in the days after a patch ships.
Perspective Coverage
4 publishers
- Builder
- Builder 33%
- Operator
- Operator 61%
- Investor
- Investor 6%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+30
- Incentives35
- Confidence65
Google's Threat Intelligence Group counted 141 flaws exploited in the wild from January to August, while monthly disclosures doubled to 10,740. Patch teams do better sorting by that exploited set than by the total, though attackers now reach some public flaws within days.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+15
- Incentives60
- Confidence50
The probes read Langflow's secret key file and grep the process environment for OpenAI and AWS credentials, which puts an AI orchestration tool on the same scanning clock as the Rails file-read bug of the same week.
Perspective Coverage
4 publishers
- Builder
- Builder 30%
- Operator
- Operator 60%
- Investor
- Investor 10%
Reality
- Evidence62
- Adoption40
- Hype gap+15
- Incentives65
- Confidence60
Rapid7 published a Metasploit module for CVE-2026-85706, an unauthenticated file read it says is already exploited against self-hosted GitLab. Every CE and EE build from 18.7 stays exposed until 19.1.8, 19.2.6 or 19.3.2.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+15
- Incentives35
- Confidence55
n8n went from $2.5bn to $5.2bn in seven months and SAP is embedding its canvas in Joule Studio, while the single number offered for agent failure, an 88% security incident rate, arrives without a population or a definition.
Reality
- Evidence42
- Adoption58
- Hype gap+30
- Incentives52
- Confidence45
Mysterium VPN counted 36,769 self-hosted AI endpoints reachable from the public internet. Ollama is the only population where the scan can prove that nothing on the host asked for credentials.
Reality
- Evidence60
- Adoption70
- Hype gap+12
- Incentives70
- Confidence58
One HTTP request runs Python on an exposed Langflow server, and Sysdig's honeypots logged exploit attempts inside a day of the March 17 advisory, before any public proof-of-concept existed. The traffic identified itself as nuclei.
Reality
- Evidence58
- Adoption34
- Hype gap+30
- Incentives78
- Confidence52
Sixteen new modules landed in the framework, ten of them exploits, and Rapid7 counts five of those against CISA's exploited list. The SonicWall entry runs September's zero-day chain from SSRF to root.
Reality
- Evidence64
- Adoption55
- Hype gap+12
- Incentives74
- Confidence62
Anil Madhavapeddy patched a path traversal bug in OCaml's cohttp and found probes for it in his logs ten minutes after opening the fix PR. His own agent had already built the exploit from a bug-class hint.
Publishers:anil.recoil.org
Reality
- Evidence52
- Adoption44
- Hype gap+14
- Incentives55
- Confidence57
Root Evidence rebuilt the exploitation clock on vendor advisory dates rather than NVD publication, and Jeremiah Grossman's team reads the resulting four-month median as a measure of inventory that stopped being maintained.
Publishers:cyrilsimonnet.substack.com
Reality
- Evidence62
- Adoption20
- Hype gap+12
- Incentives58
- Confidence55
VulnCheck logged more than 15,000 successful hits on decoy Langflow instances while eleven new flaws joined the exploited-in-the-wild list, on a product whose first deployment model expects to face the internet.
Reality
- Evidence60
- Adoption66
- Hype gap+18
- Incentives80
- Confidence55
Rapid7 describes eleven of the sixteen additions, and eight of those are scanners rather than exploits. The unauthenticated file reads and SQL injections carry the real pressure this quarter, well ahead of the two Tenable modules.
Reality
- Evidence63
- Adoption34
- Hype gap+24
- Incentives69
- Confidence58
CVE-2026-48519 lets anyone holding a shared Langflow playground link supply their own Python inside the build request. The exposure follows a user clicking share, so it lives in flow state rather than in server config.
Reality
- Evidence78
- Adoption
- Insufficient
- Hype gap−10
- Incentives35
- Confidence66
Censys counts more than 294,000 public IPs running one of 43 AI or LLM tools, up from roughly 183,000 in October 2025. The two platforms it names for growth, Langflow and LiteLLM, both carry KEV-listed flaws.
Reality
- Evidence44
- Adoption63
- Hype gap+16
- Incentives71
- Confidence50
Ninety days of Wiz honeypot telemetry shows tooling written for LiteLLM's internals, including a config test endpoint that spawns whatever command it is handed and a miner whose output comes home inside the MCP protocol.
Reality
- Evidence62
- Adoption66
- Hype gap+12
- Incentives72
- Confidence55
The vendor reports 10-plus CVEs and up to 200,000 exposed instances, and says Anthropic declined to change the protocol, describing the behaviour as expected.
Publishers:ox.security
Reality
- Evidence32
- Adoption34
- Hype gap+46
- Incentives86
- Confidence33
Tenable says autonomous agents mapped 21 Taiwanese government systems in four days. The way in was discoverable federation configuration and weak credentials, not a novel exploit.
Reality
- Evidence38
- Adoption54
- Hype gap+28
- Incentives82
- Confidence44
Rapid7's latest wrap-up ships working exploit code for seven separately documented flaws, including an unauthenticated Joomla web shell and a Linux kernel LPE. Reprioritize this week, not next cycle.
Reality
- Evidence74
- Adoption52
- Hype gap+22
- Incentives71
- Confidence63