CVE-2025-3248
Known exploited · CISA KEV
CVSS 9.8 CRITICAL: langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. EPSS 100% (100th percentile).
CISA federal remediation date May 26 · date passed
Ransomware & Extortion · Ransomware
The shift is not a new ransomware breakthrough. A small set of gangs is taking most of the claims, and AI is helping them write extortion messages that sound more credible and personal without changing the underlying playbook.
GuidePoint’s Q2 2026 report counts 2,279 claimed victims, up 7% from Q1 and 43% year over year. The five most active groups claimed more than 40% of attacks, with Qilin and The Gentlemen driving much of the volume; the report also says LLMs are being used to scale ransom and extortion messaging, not to invent a new technical attack class.
For defenders, the weak tell is no longer sloppy writing. The pressure is coming from more believable, industrialized demands backed by a market that is concentrated enough to absorb disruptions and keep producing claims.
10 sources · Jul 9
Known exploited · CISA KEV
CVSS 9.8 CRITICAL: langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. EPSS 100% (100th percentile).
CISA federal remediation date May 26 · date passed
Cybersecurity Dive
Ransomware ecosystem grows, but ‘four-headed monster’ dominates
AI is helping hackers, a new report finds, but mostly by automating very human behaviors.
originalGraham Cluley
Smashing Security podcast #475: JadePuffer - the AI that ran a ransomware attack all by itself
A 15-year-old boy asked a chatbot for help – and cancelled nearly 47,000 anime streaming subscriptions in under four hours. Meanwhile, researchers have documented the first fully autonomous…
originalTechCrunch Security
The 'first' AI-run ransomware attack still needed a human | TechCrunch
An AI agent carried out the technical execution of a real-world ransomware attack for the first known time, but new details show a human still chose the victim, set up the infrastructure, and supplied stolen credentials — meaning it wasn't quite the fully autonomous cybercrime debut that last week's headlines suggested.
originalPart of the PlainSec briefing for 2026-07-06
Every edition of this story: Ransomware Claims Concentrate as AI Polishes Pressure