View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Langflow RCE exploited to deploy Monero miners on AI endpoints

🚨 ACTIVE EXPLOITS & INCIDENTS

πŸ”“ VULNERABILITIES & CVEs

πŸ•΅οΈ THREAT RESEARCH & DEEP DIVES

  • RustDuck Botnet Rebuilds in Rust to Hijack Routers and Servers for DDoS β€” The Hacker News QiAnXin XLab tracks RustDuck, a fast-evolving two-stage botnet targeting home routers, IP cameras, Android boxes, and unsecured servers. Written in Rust, it rapidly adapts to build a large DDoS network, highlighting the growing threat to IoT and edge devices.
  • Microsoft Warns Poisoned MCP Tool Descriptions Can Make AI Agents Leak Data β€” The Hacker News / Microsoft Security Blog Microsoft Incident Response research demonstrates how attackers can poison AI agent tool descriptions (MCP tools) to exfiltrate sensitive company data without triggering alarms. This subtle manipulation turns trusted AI agents into covert data loss vectors, emphasizing the need for enhanced AI agent monitoring and validation.

πŸ“‹ VENDOR BULLETINS & ADVISORIES

  • Securing AI agents: When AI tools move from reading to acting β€” Microsoft Security Blog Microsoft details mitigation strategies against MCP tool poisoning attacks that hijack AI agents to perform unauthorized actions. Guidance includes detection, containment, and prevention best practices for organizations deploying AI automation.
  • What’s new in Microsoft Security: June 2026 β€” Microsoft Security Blog June updates focus on strengthening identity and multicloud security foundations, data protection, and securing AI developer workflows. Key improvements target AI innovation environments and cloud-native security controls.
  • Accelerating the quantum-safe timeline β€” Microsoft Security Blog Microsoft announces accelerated efforts for quantum-safe cryptography readiness, urging organizations to begin early transitions to post-quantum algorithms to mitigate emerging quantum computing threats.

πŸ“° LESSER-KNOWN / UNDER-REPORTED

  • Fake Perplexity extension on Chrome Web Store tracked searches β€” BleepingComputer A malicious Chrome extension impersonating the Perplexity AI answer engine was found intercepting user search traffic and collecting browsing data. Users should audit installed extensions and remove suspicious AI-related plugins.

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check