security1 publisher
A nuclei template hit Langflow's unauthenticated build endpoint 20 hours after disclosure
One HTTP request runs Python on an exposed Langflow server, and Sysdig's honeypots logged exploit attempts inside a day of the March 17 advisory, before any public proof-of-concept existed. The traffic identified itself as nuclei.
Publishers:sysdig.com
Reality
- Evidence58
- Adoption34
- Hype gap+30
- Incentives78
- Confidence52