IT SPARC Cast

← IT SPARC Cast7 Aug · 9 min

China's AI Hacked This CVE Autonomously — Inside the DeepSeek Remote Code Execution Campaign

China's AI Hacked This CVE Autonomously — Inside the DeepSeek Remote Code Execution Campaign7 Aug9 min

This week on IT SPARC Cast – CVE of the Week, John and Lou cover three newly exploited vulnerabilities affecting Langflow, Apache Tomcat, and N-able N-central. While each vulnerability is serious on its own, the bigger story is how attackers are increasingly using AI to identify targets, automate reconnaissance, and accelerate attacks.

The discussion also explores recent research showing threat actors using AI to prioritize targets, why network anomaly detection is becoming more important than ever, and why organizations can no longer afford to wait for monthly patch cycles. If you’re responsible for enterprise IT, this episode highlights why continuous patching and AI-assisted defense are quickly becoming necessities.

📄 Show Notes

🚨 CVE of the Week

This week we’re covering three newly exploited vulnerabilities that every enterprise IT team should know about.

Langflow (CVE-2026-9198 | CVSS 9.8)

A critical unauthenticated remote code execution vulnerability affecting default Langflow deployments. Particularly concerning because Langflow is widely used for building AI workflows and agent-based applications.

Fixed in: Langflow 1.10.1

Apache Tomcat (CVE-2026-34486 | CVSS 7.5)

A vulnerability affecting encrypted cluster communication in Apache Tomcat. Successful exploitation can expose sensitive cluster traffic and weaken security in highly available enterprise deployments.