Attackers are actively exploiting CVE-2025-3248, a critical RCE vulnerability in Langflow's code validation API, to deploy a customized Gafgyt DDoS bot on AI development servers. The bot uses a modified RC4 stream cipher for C2 communications and is optimized purely for network flooding attacks (UDP, TCP, HOLD, Junk). AI infrastructure is targeted due to high bandwidth availability, shadow IT deployment practices, and permissive egress filtering.
CVE-2025-3248
2 posts
Langflow Exploited to Build Custom DDoS Gafgyt Botnets 13th July – Threat Intelligence Report This weekly threat intelligence bulletin covers multiple significant incidents including autonomous LLM-driven ransomware (JadePuffer), a cryptocurrency supply chain compromise via malicious npm packages, and three critical CVEs affecting Langflow, Tenda routers, and Linux KVM. Iran-linked Cavern Manticore and China-linked UAT-7810 were profiled targeting Israeli and networking infrastructure respectively. The report also highlights risks in AI development tools where hidden malicious instructions in open-source files could achieve RCE through Claude Code and OpenAI Codex.