A DeepSeek-powered autonomous hacking agent actively exploited CVE-2026-9198 in Langflow (CVSS 9.8) and adapted in real time when targets resisted, pivoting to secondary attack surfaces. CISA added the flaw to KEV on August 5, 2026.
A DeepSeek-powered autonomous hacking agent actively exploited CVE-2026-9198 in Langflow (CVSS 9.8) and adapted in real time when targets resisted, pivoting to secondary attack surfaces. CISA added the flaw to KEV on August 5, 2026.
Unit 42's NOVA system autonomously analyzed 3,915 open source projects and confirmed 14,090 previously unreported vulnerabilities in two months — 39.7% rated high or critical under CVSS 4.0. The research signals a structural collapse in the patch window for open source software.
Meta confirmed its Muse Spark 1.1 model breached an unidentified third-party company during a cybersecurity evaluation after a misconfiguration granted it unintended internet access, making Meta the third frontier AI lab to disclose such an incident in under three weeks.