The Matthew Chapman Podcast

If You Run Langflow Or OpenVSwitch You Need To Act Today

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 4:19

Here is your briefing for Wednesday, August 5, 2026. The U.S. Cybersecurity and Infrastructure Security Agency added three flaws to its Known Exploited Vulnerabilities catalog on August 5, citing evidence of active exploitation in the wild. CVE-2026-9198 is a code injection vulnerability in Langflow that allows unauthenticated attackers to achieve full remote code execution on default deployments. It was fixed in July with version 1.10.1. CVE-2026-34486 is a missing encryption of sensitive data flaw in Apache Tomcat that allows a bypass of EncryptInterceptor. Fixed in April. CVE-2026-18556 is an authentication bypass in N-able N-central. An incomplete fix for the N-central issue prompted the addition. These are not theoretical. Attackers are already using them. CISA's move is a reminder that the window between disclosure and exploitation keeps shrinking. Langflow in particular is popular in AI and data pipeline environments. If you're running it exposed, you're already late.  A memory corruption flaw in the Linux kernel's Open vSwitch datapath gives ordinary local users a path to root on a broad set of default-configured distributions. A public exploit ships with pre-built records for roughly 800 kernel builds. The vulnerability, tracked as CVE-2026-64531 with a CVSS score of 7.8, was disclosed by researcher Asim Manizada on July 28. The bug sits in the kernel datapath, not the userspace daemon. An attacker needs no existing OVS bridge, no running ovs-vswitchd, and no host-level CAP_NET_ADMIN. On affected systems where the OVS kernel datapath is available and unprivileged user namespaces are enabled, an ordinary user can create private namespaces with unshare, gain the capability inside that namespace, and reach the vulnerable flow-installation path. This is a local privilege escalation with a working public exploit and broad hardware coverage. If your fleet runs Open vSwitch — and many do for container networking — this one needs attention now. Kali365 is turning a legitimate Microsoft login into a gateway to corporate data. The phishing kit targets US organizations with attacker-controlled device codes that victims approve on Microsoft's real authentication page. Once access and refresh tokens are issued, attackers may retain access to email, documents, and cloud resources. ANY.RUN telemetry records more than 80 public sessions linked to the campaign each week, with the United States as the main target. The kit uses SharePoint-themed lures and other enterprise-looking pages to draw victims into the device code flow. This is device code phishing at scale, and it's working. CrowdStrike's recent threat hunting report noted a 1,500% increase in device code phishing in the first half of 2026 alongside a doubling of vishing. The technique bypasses many traditional controls because the victim is actively approving the request on Microsoft's own infrastructure. If your org still relies on device code flows without additional verification, you're exposed. A cluster of 77 extensions on the Open VSX marketplace has been found to impersonate legitimate developer tools while transmitting information about the systems and development environments on which they were installed. The packages were uploaded between July 26 and August 1 and removed as of August 3. In most cases the extensions send little more than the machine's hostname. In nineteen of them they send a detailed description of the machine, the repository open in the editor, and the CI system the editor is running inside. Fifty-eight were lightweight reconnaissance tools. The rest were more aggressive payloads. This is supply chain compromise at the editor level. Developers install these things thinking they're getting a useful utility. Instead they're phoning home with exactly the kind of context an attacker needs for targeted follow-on operations. The fact that it took a third-party security firm to catch this, rather than

Support the show

Wednesday Cyber Briefing Kickoff

SPEAKER_00

Here is your briefing for Wednesday, august fifth, twenty twenty

CISA KEV Adds Three Exploits

SPEAKER_00

six. The U.S. Cybersecurity and Infrastructure Security Agency added three flaws to its known exploited vulnerabilities catalog on august fifth, citing evidence of active exploitation in the wild. CVE twenty twenty six-9198 is a code injection vulnerability in Langflow that allows unauthenticated attackers to achieve full remote code execution on default deployments. It was fixed in July with version 1.1C CVE 2026-34486 is a missing encryption of sensitive data flaw in Apache Tomcat that allows a bypass of encrypt interceptor. Fixed in April, CVE 2026-18556 is an authentication bypass and enable NCentral. An incomplete fix for the NCentral issue prompted the addition. These are not theoretical, attackers are already using them. CESA's move is a reminder that the window between disclosure and exploitation keeps shrinking. Langflow in particular is popular in AI and data pipeline environments. If you're running it exposed,

Linux OpenVSwitch Local Root Path

SPEAKER_00

you're already late. A memory corruption flaw in the Linux kernel's Open VSwitch data path gives ordinary local users a path to route on a broad set of default configured distributions. A public exploit ships with pre-built records for roughly 800 kernel builds. The vulnerability tracked as CVE 2026-64531 with a CVSS score of 7.8, was disclosed by researcher ASE Manazata on July 28th. The bug sits in the kernel data path, not the user space daemon. An attacker needs no existing OVS bridge, no running OVS V switch D, and no host level CapNet editna. On affected systems where the OVS kernel data path is available and unprivileged user namespaces are enabled, an ordinary user can create private namespaces with Unshare, gain the capability inside that namespace, and reach the vulnerable flow installation path. This is a local privilege escalation with a working public exploit and broad hardware coverage. If your fleet runs OpenVSwitch and many do for container networking, this one needs attention now.

Device Code Phishing Hits Microsoft

SPEAKER_00

Cali 365 is turning a legitimate Microsoft login into a gateway to corporate data. The phishing kit targets US organizations with attacker controlled device codes that victims approve on Microsoft's real authentication page. Once access and refresh tokens are issued, attackers may retain access to email, documents, and cloud resources. Anywhite earned telemetry records more than 80 public sessions linked to the campaign each week, with the United States as the main target. The kit uses SharePoint themed lures and other enterprise looking pages to draw victims into the device code flow. This is device code phishing at scale and it's working. CrowdStrike's recent threat hunting report noted a 1,500% increase in device code phishing in the first half of 2026 alongside a doubling of phishing. The technique bypasses many traditional controls because the victim is actively approving the request on Microsoft's own infrastructure. If your org still relies on device code flows without additional verification, you're exposed.

OpenVSX Extensions Leak Dev Context

SPEAKER_00

A cluster of seventy seven extensions on the OpenVSX marketplace has been found to impersonate legitimate developer tools while transmitting information about the systems and development environments on which they were installed. The packages were uploaded between july twenty sixth and august fourth and removed as of august third. In most cases, the extensions send little more than the machine's hostname. In nineteen of them, they send a detailed description of the machine, the repository open in the editor, and the CI system. The editor is running inside. Fifty eight were lightweight reconnaissance tools. The rest were more aggressive payloads. This is supply chain compromise at the editor level. Developers install these things thinking they're getting a useful utility. Instead, they're phoning home with exactly the kind of context an attacker needs for targeted follow-on operations. The fact that it took a third party security firm to catch this, rather than the marketplace itself, says something about review processes on open extension registries.

One Theme Expanding Attack Surface

SPEAKER_00

Four stories. One through line. The attack surface is expanding faster than the defenses. AI agents are demonstrating real adversarial behavior in live tests. Kernel and application vulnerabilities are being weaponized in days, not months. Fishing kits are abusing legitimate auth flows at scale, and even the tools developers rely on every day are being poisoned at the source. The easy assumptions that open source is inherently trustworthy, that our models won't turn on us, that patch windows are measured in weeks are breaking down in real

Closing Patch Fast Stay Sharp

SPEAKER_00

time. That's the briefing. Stay sharp, patch your systems, and we'll see you tomorrow.