Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners, Highlighting Growing Concerns Over AI-Infused Cybersecurity Threats


Seven Exploited Flaws Linked to AI-Powered Tools and Platforms, Highlighting Growing Concerns Over AI-Infused Cybersecurity Threats

  • The CISA has added seven security flaws to its KEV catalog, linked to AI-powered tools and platforms.
  • The identified vulnerabilities have been associated with high-profile attacks, including those involving Qilin (aka Agenda) ransomware and Kestra OSS.
  • The attacks have been characterized by the use of AI-powered tools and platforms to bypass authentication, establish persistence, and execute arbitrary code.
  • The vulnerabilities have been exploited by attackers to deploy reverse shells and minted admin tokens.
  • The CISA has recommended that organizations prioritize AI security and take steps to address the identified vulnerabilities.



  • The U.S. Cybersecurity and Infrastructure Security Agency (CISA) recently announced the addition of seven security flaws to its Known Exploited Vulnerabilities (KEV) catalog, a move that underscores the growing concerns over AI-infused cybersecurity threats. The seven identified vulnerabilities, which were exploited by attackers, have been associated with various AI-powered tools and platforms, including LiteLLM, Flowise, and ChromaDB. These vulnerabilities have been linked to several high-profile attacks, including those involving the Qilin (aka Agenda) ransomware and the Kestra OSS vulnerability.

    The addition of these seven vulnerabilities to the KEV catalog serves as a stark reminder of the evolving threat landscape and the need for organizations to prioritize AI security. The CISA's efforts to identify and address these vulnerabilities are a testament to the agency's commitment to protecting the nation's critical infrastructure from AI-powered attacks.

    Among the identified vulnerabilities, CVE-2026-83548 and CVE-2026-83549 have been linked to SonicWall SMA 1000 Appliances, while CVE-2026-9586 has been associated with Sangoma Switchvox. These vulnerabilities have been exploited by attackers to deploy reverse shells and minted admin tokens, further highlighting the threat posed by AI-infused attacks.

    The CISA's efforts to address these vulnerabilities have been augmented by reports from other organizations, including Horizon3.ai and watchTowr, which have documented the use of these vulnerabilities in attacks. The development of these attacks has been characterized by the use of AI-powered tools and platforms to bypass authentication, establish persistence, and execute arbitrary code.

    The attacks have been linked to the Qilin (aka Agenda) ransomware, which has been associated with the exploitation of CVE-2026-83548 and CVE-2026-83549. The ransomware has been used to compromise organizations and steal sensitive data, further highlighting the threat posed by AI-infused attacks.

    In addition to the attacks linked to the Qilin ransomware, the CISA has also documented the exploitation of CVE-2026-49869, which has been linked to Kestra OSS. The vulnerability has been used to establish a reverse shell, conduct Docker container environment discovery, and deploy a cryptocurrency miner.

    The attacks have also been characterized by the use of AI-powered tools and platforms to probe model enumeration endpoints and steal sensitive data. The use of these tools and platforms has further highlighted the threat posed by AI-infused attacks, which can be used to bypass authentication, establish persistence, and execute arbitrary code.

    The CISA's efforts to address these vulnerabilities have been augmented by reports from other organizations, including Microsoft and Wiz, which have documented the use of these vulnerabilities in attacks. The development of these attacks has been characterized by the use of AI-powered tools and platforms to bypass authentication, establish persistence, and execute arbitrary code.

    The attacks have been linked to the exploitation of various AI-powered tools and platforms, including LiteLLM, Flowise, and ChromaDB. These tools and platforms have been used to bypass authentication, establish persistence, and execute arbitrary code. The use of these tools and platforms has further highlighted the threat posed by AI-infused attacks.

    In response to the growing threat landscape, the CISA has recommended that organizations prioritize AI security and take steps to address the identified vulnerabilities. The agency has also recommended that organizations monitor AI workloads according to their control-plane role, rather than treating them as isolated applications.

    The development of AI-powered tools and platforms has transformed the threat landscape, and organizations must take steps to address the identified vulnerabilities. The CISA's efforts to identify and address these vulnerabilities serve as a stark reminder of the need for organizations to prioritize AI security.

    The growing threat landscape has highlighted the need for organizations to take proactive steps to address the identified vulnerabilities. The CISA's efforts to identify and address these vulnerabilities serve as a testament to the agency's commitment to protecting the nation's critical infrastructure from AI-powered attacks.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/CISA-Adds-Seven-Exploited-Flaws-as-Attackers-Deploy-Reverse-Shells-and-Crypto-Miners-Highlighting-Growing-Concerns-Over-AI-Infused-Cybersecurity-Threats-ehn.shtml

  • https://thehackernews.com/2026/09/cisa-adds-seven-exploited-flaws-as.html

  • https://www.sepe.gr/en/it-technology/cybersecurity/22769472/cisa-adds-seven-exploited-flaws-as-attackers-deploy-reverse-shells-and-crypto-miners/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-83548

  • https://www.cvedetails.com/cve/CVE-2026-83548/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-83549

  • https://www.cvedetails.com/cve/CVE-2026-83549/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-9586

  • https://www.cvedetails.com/cve/CVE-2026-9586/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-49869

  • https://www.cvedetails.com/cve/CVE-2026-49869/

  • https://blog.pypi.org/posts/2026-04-02-incident-report-litellm-telnyx-supply-chain-attack/

  • https://github.com/BerriAI/litellm/issues/24512

  • https://app.opencve.io/cve/?vendor=flowiseai

  • https://feedly.com/cve/vendors/flowiseai

  • https://www.bleepingcomputer.com/news/security/max-severity-flaw-in-chromadb-for-ai-apps-allows-server-hijacking/

  • https://labs.cloudsecurityalliance.org/research/csa-research-note-chromadb-rce-ai-infrastructure-security-20/

  • https://dailysecurityreview.com/resources/threat-actors-resources/qilin-agenda-ransomware-the-credential-stealers/

  • https://www.sentinelone.com/anthology/agenda-qilin/


  • Published: Thu Sep 3 02:18:50 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us