Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Check Point Research discovered three vulnerabilities in LangGraph, an open-source AI agent framework with over 50 million monthly downloads. Two vulnerabilities chain to remote code execution: a SQL injection in the SQLite checkpointer and an unsafe msgpack deserialization.
Check Point Research uncovered three vulnerabilities in LangGraph, an open-source framework for stateful AI agents with over 50 million monthly downloads. The most critical issues include a SQL injection flaw (CVE-2025-67644) in the SQLite checkpointer and an unsafe msgpack deserialization vulnerability (CVE-2026-28277), which can be chained for remote code execution.
Check Point Research uncovered three vulnerabilities in LangGraph, an open-source AI framework with over 50 million monthly downloads, which could allow attackers to execute remote code. The first flaw (CVE-2025-67644) is a SQL injection in the SQLite checkpointer that lets attackers inject malicious SQL queries through user-controlled filters, potentially leading to arbitrary deserialization of attacker-controlled data.
Check Point Research discovered three vulnerabilities in LangGraph, an open-source AI agent framework with over 50 million monthly downloads. Two vulnerabilities chain to remote code execution: a SQL injection in the SQLite checkpointer and an unsafe msgpack deserialization.
FortiGuard Labs analyzes a multi-stage malware campaign that uses fake AI-themed documents, hidden PowerShell scripts, AutoHotkey loaders, and process injection to deploy AsyncRAT and maintain remote access.
Cybercriminals are exploiting public interest in artificial intelligence to distribute malware, according to FortiGuard Labs. The campaign involves multi-stage attacks where victims are tricked into opening fake AI-themed documents, which then execute hidden PowerShell scripts.