← SCRUDGE REPORT
FILED BY ADEQUATE · DARPA-HRO-11-C-0031
Dark Reading · TUESDAY, SEPTEMBER 1, 2026

Critical Langflow Vulnerability Exploited Before Patch Was Deployed

Langflow, an open source framework, had a critical vulnerability. It was exploited in the wild before a patch existed. The critical rating came after the exploitation started. Severity is assigned retroactively when the breach is discovered, not when the flaw opens.

This happens every cycle. Vulnerabilities achieve criticality only after proof of concept. The delay between detection and rating is the space where damage compounds. No organization has filed to change the system. The system generates the data that proves itself inevitable.

The next vulnerability is already in use. It will be rated critical once someone notices. By then the pattern will have repeated and the interval will have seemed natural.

Dark Reading
READ ORIGINAL FILING →
AI Identifies Thousands of Security Vulnerabilities. Almost None Are Patched.
The Decoder
Palo Alto Zero-Day Exploited in Campaign with Hallmarks of Chinese State Hacking
SecurityWeek
Google Confirms Hackers Used AI to Develop a Working Zero-Day Exploit
TechRepublic AI
'HalluSquatting' Attack Turns AI's Invented Package Names Into Malware Delivery Routes
Tom's Hardware
'Zoomsday' Exploit Enabling Full Device Takeover Was Found by AI in 20 Prompts
Tom's Hardware
Hackers Use AI to Generate Exploits for Siemens Controllers Governing US Water Infrastructure
Tom's Hardware