- Critical path traversal and arbitrary file write vulnerability in Langflow POST /api/v2/files endpoint
ThreatNoir Morning Brief — April 13
Morning Review in IT Security — April 13, 2026
The cybersecurity landscape continues to evolve with alarming speed as artificial intelligence tools become weapons in the hands of sophisticated threat actors. Today's briefing covers critical incidents spanning AI-powered nation-state attacks, zero-day vulnerabilities in emerging platforms, and mobile exploit chains circulating in underground markets.
AI-Powered Attack Compromises Nine Mexican Government Agencies
A single threat actor leveraged ChatGPT and Claude to orchestrate one of the most technically advanced campaigns against Mexican government infrastructure. The campaign ran from late December 2025 through mid-February 2026, targeting nine separate government agencies and resulting in the exfiltration of hundreds of millions of citizen records. The attacker utilized Claude Code and GPT-4.1 to automate and enhance the attack methodology, demonstrating how modern AI tools can amplify the capabilities of individual operators. Source: Hacker Used Claude Code, GPT-4.1 to Exfiltrate Hundreds of Millions of Mexican Records
Critical Path Traversal Vulnerability in Langflow
A critical vulnerability designated CVE-2026-5027 has been identified in Langflow's file handling mechanism. The flaw exists in the POST /api/v2/files endpoint and allows path traversal combined with arbitrary file write capabilities. With a CVSS score of 8.8, this vulnerability poses severe risk to systems running affected versions of Langflow. The vulnerability enables unauthenticated attackers to compromise systems through a single malicious request. Source: CVE-2026-5027: Critical Path Traversal / Arbitrary File Write vulnerability in Langflow
iOS Zero-Day Exploit Chain Sold on Underground Markets
A full-chain one-click exploit targeting iOS versions 18 through 18.7 is being actively marketed on popular cybercrime forums. The exploit, attributed to threat actor rosestealer and labeled "EL Muncho," is bundled with a data stealer malware variant called GHOSTBLADE. The combination of a complete exploit chain with integrated malware functionality represents a significant threat to iOS users, as the single-click nature of the attack dramatically lowers the technical barrier for attackers. Source: A full-chain one-click exploit for iOS 18 through 18.7, bundled with a bonus stealer called "GHOSTBLADE"
The convergence of AI-assisted attacks, unpatched critical vulnerabilities, and sophisticated mobile exploits underscores the urgent need for organizations to enhance their detection capabilities, apply security updates immediately, and implement AI-aware threat modeling in their defensive strategies.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- GHOSTBLADEInformation stealer malware bundled with EL Muncho exploit
- BACKUPOSINT.pyCustom 17,550-line tool used to move stolen data from 305 internal servers to OpenAI's systems