Vulnerability researchers observe mass automated scanning and exploitation of Langflow AI visual frameworks, exfiltrating OpenAI and AWS secrets while deploying botnets.
Prompt injection is now OWASP’s top LLM risk with reported success rates of 50–84%. Organisations are shipping agents into production well ahead of their controls.
Gravitee says 88% of organisations had a confirmed or suspected AI agent incident, while 82% of executives trust their policy. Both figures, one population.
OX Security and VulnCheck disclosed CVE-2026-82533 in DeepSeek Harness, where prompt injection allowed sandboxed AI coding agents to disable their own security isolation.