Critical Langflow Vulnerability Exploited as Attacks on AI Platform Rise
Attacks exploiting CVE-2026-0768, a critical vulnerability in the Langflow low-code AI platform, are rising amid growing adversary attention this year.
CVE-2026-0768 is a critical vulnerability in Langflow, a low-code AI development platform, with exploitation attacks now rising. Dark Reading notes the platform has drawn increasing adversary attention in 2026. Organizations running exposed Langflow instances face elevated risk and should patch promptly and review instances for compromise.
From Protocols to Evidence: Bounded Claims for AI in Service of the Common Good
Paper proposes a rupture test and RISE AI architecture for evidence-bounded responsible-AI claims, framed via EU AI Act and NIST AI RMF.
The paper argues AI deployment intervenes in pre-existing institutional failures of responsiveness, belonging, care, and accountability, and must therefore evaluate both the system and the institutional rupture it enters. It reviews how the EU AI Act, NIST AI RMF, and ISO/IEC 42001 translate principles into protocols, and draws on Pope Leo XIV's Magnifica Humanitas to develop a rupture test linking institutional baselines to system evaluation. It distinguishes evidence-bounded deployment from measurement-bounded governance and introduces RISE AI, an architecture for bounded claims about Responsibility, Inclusivity, Safety, and Empowerment.
What the Data Says About AI in Security Operations in 2026
Prophet Security's 2026 survey of 250+ security pros: 40% use AI daily; AI users report 25%+ faster investigations and rising AI-driven attacks.
Prophet Security's State of AI in Security Operations 2026 report, based on a survey of 250+ cybersecurity professionals, found 40% of security teams use AI daily and only 4% have no adoption plans. Teams average 100 daily alerts (up to 1,000 at large firms), leave 28% of alerts uninvestigated, and 60% of respondents said missed alerts led to breaches or downtime. Among AI adopters, 72% report at least 25% faster investigations, 56% observed increased AI-driven attacks, and no respondents grant AI full unsupervised autonomy. Data privacy (44%) and explainability (41%) top the adoption hurdles.
Why "Shady AI" is Security's Next Big Governance Problem
Opinion piece argues approved-but-ungoverned AI agent use ('shady AI') is a growing enterprise risk, citing a Meta Sev 1 data-exposure incident.
In March 2026, an approved AI agent at Meta posted a forum answer publicly, exposing sensitive company and user data to unauthorized employees for over two hours and triggering a Sev 1 incident. The author contrasts shadow AI (unapproved tools) with 'shady AI' (approved tools used in unapproved or unanticipated ways), arguing the latter is harder to govern because it operates inside the organization's visibility. A July 2026 SANS survey found 76% of security teams now have a role in governing enterprise AI. The piece recommends governance-by-default environments with built-in permissions, access controls, and monitoring rather than policy and training alone.