{"version":"1.0","type":"rich","provider_name":"Acast","provider_url":"https://acast.com","height":250,"width":700,"html":"<iframe src=\"https://embed.acast.com/$/66cf6d924960e4eb18d4aa8d/6a74decfd410c25118b1bb67?\" frameBorder=\"0\" width=\"700\" height=\"250\"></iframe>","title":"China's AI Hacked This CVE Autonomously — Inside the DeepSeek Remote Code Execution Campaign","thumbnail_width":200,"thumbnail_height":200,"thumbnail_url":"https://open-images.acast.com/shows/66cf6d924960e4eb18d4aa8d/1786044041702-6ddee374-7cd8-4c13-8423-c6a389e695d6.jpeg?height=200","description":"<p>This week on <strong>IT SPARC Cast – CVE of the Week</strong>, John and Lou cover three newly exploited vulnerabilities affecting <strong>Langflow, Apache Tomcat, and N-able N-central</strong>. While each vulnerability is serious on its own, the bigger story is how attackers are increasingly using AI to identify targets, automate reconnaissance, and accelerate attacks.</p><p><br></p><p>The discussion also explores recent research showing threat actors using AI to prioritize targets, why network anomaly detection is becoming more important than ever, and why organizations can no longer afford to wait for monthly patch cycles. If you’re responsible for enterprise IT, this episode highlights why continuous patching and AI-assisted defense are quickly becoming necessities.</p><p><br></p><p>⸻</p><p><br></p><p>📄<strong> Show Notes</strong></p><p><br></p><p>🚨<strong> CVE of the Week</strong></p><p><br></p><p>This week we’re covering <strong>three newly exploited vulnerabilities</strong> that every enterprise IT team should know about.</p><p><br></p><p><strong>Langflow (CVE-2026-9198 | CVSS 9.8)</strong></p><p><br></p><p>A critical unauthenticated remote code execution vulnerability affecting default Langflow deployments. Particularly concerning because Langflow is widely used for building AI workflows and agent-based applications.</p><p><br></p><p><strong>Fixed in:</strong> Langflow 1.10.1</p><p><br></p><p>⸻</p><p><br></p><p><strong>Apache Tomcat (CVE-2026-34486 | CVSS 7.5)</strong></p><p><br></p><p>A vulnerability affecting encrypted cluster communication in Apache Tomcat. Successful exploitation can expose sensitive cluster traffic and weaken security in highly available enterprise deployments.</p><p><br></p><p><strong>Patched in:</strong></p><p><br></p><p><br></p><ul><li>Tomcat 11.0.21</li><li>Tomcat 10.1.54</li><li>Tomcat 9.0.117</li></ul><p><br></p><p>⸻</p><p><br></p><p><strong>N-able N-central (CVE-2026-18556 &amp; CVE-2026-18577)</strong></p><p><br></p><p>An authentication bypass vulnerability followed by a second patch after the original fix proved incomplete. Both vulnerabilities are now considered actively exploited.</p><p><br></p><p>⸻</p><p><br></p><p>🤖<strong> AI Is Changing the Threat Landscape</strong></p><p><br></p><p>Researchers observed attackers using AI to help identify and prioritize targets before launching attacks.</p><p><br></p><p>The takeaway isn’t simply that AI is being used—it’s that attackers are becoming faster and more efficient.</p><p><br></p><p>John and Lou discuss why defenders must respond with:</p><p><br></p><p><br></p><ul><li>AI-assisted security tools</li><li>Network anomaly detection</li><li>Continuous monitoring</li><li>Faster patch deployment</li></ul><p><br></p><p>The only practical way to keep pace with AI-assisted attacks is to use AI as part of your defense strategy.</p><p><br></p><p>⸻</p><p><br></p><p>🛠️<strong> Recommended Actions</strong></p><p><br></p><p><br></p><ul><li>Patch Langflow, Tomcat, and N-central immediately.</li><li>Inventory your environment for unauthorized Tomcat deployments.</li><li>Enable continuous vulnerability monitoring.</li><li>Deploy network anomaly detection where possible.</li><li>Move toward continuous patching rather than monthly maintenance windows.</li><li>Review AI security policies and detection capabilities.</li></ul><p><br></p><p>⸻</p><p><br></p><p>💬<strong> Mail Bag</strong></p><p><br></p><p>Listener BJ appreciated that last week’s episode focused on the enterprise impact of OpenWRT instead of treating it as simply another home router vulnerability.</p><p><br></p><p>John and Lou discuss why many open-source technologies quietly power enterprise infrastructure—and why understanding those hidden dependencies is becoming increasingly important.</p><p><br></p><p>⸻</p><p><br></p><p>📣<strong> Wrap Up</strong></p><p><br></p><p>How is your organization preparing for AI-assisted cyberattacks? Is continuous patching part of your strategy?</p><p><br></p><p>📧 feedback@itsparccast.com</p><p><br></p><p><strong>Follow IT SPARC Cast</strong></p><p><br></p><p><strong>IT SPARC Cast</strong></p><p>@ITSPARCCast on X</p><p>https://www.linkedin.com/company/sparc-sales/ on LinkedIn</p><p><br></p><p><strong>John Barger</strong></p><p>@john_Video on X</p><p>https://www.linkedin.com/in/johnbarger/ on LinkedIn</p><p><br></p><p><strong>Lou Schmidt</strong></p><p>@loudoggeek on X</p><p>https://www.linkedin.com/in/louis-schmidt-b102446/ on LinkedIn</p>","author_name":"John Barger"}