AI & ML Platforms
Security vulnerabilities in AI and machine learning platforms — LLM workflow builders (Langflow), business-intelligence tools (Metabase), and AI agent infrastructure. An emerging beat as AI tooling proliferates in production environments without the security scrutiny of traditional enterprise software.

Metabase Patches CVSS 10 Zero-Day Under Active Exploit
Metabase has released a patch for the max-severity unauthenticated SQL injection zero-day confirmed in active exploitation since August 8. Update now. No CVE assigned yet.

Metabase Zero-Day: CVSS 10 Exploited in the Wild
Unauthenticated SQL injection in Metabase BI gives attackers admin access. Exploitation confirmed, no CVE assigned. Take your instance offline if it's reachable from untrusted networks.

ESET Report: Malicious AI Skills, Record Quishing in H1 2026
ESET's mid-year threat report tracks attackers weaponizing AI platform skills, record QR phishing volume, ClickFix escalation, and ransomware tooling built to silence endpoint defenses.