Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Posts claim Kim Jong Un demanded firing squad for Epstein associates. There’s no proof

    July 30, 2026

    Thousands evacuated in Crete but Spanish PM ends wildfire emergency

    July 30, 2026

    Tusk: ‘Everything indicates’ Russian cruise missile hit Poland

    July 30, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Posts claim Kim Jong Un demanded firing squad for Epstein associates. There’s no proof
    • Thousands evacuated in Crete but Spanish PM ends wildfire emergency
    • Tusk: ‘Everything indicates’ Russian cruise missile hit Poland
    • Only the Middle East crisis is preventing a drop in UK interest rates | Interest rates
    • Virtual interviews don’t show bosses your personality, says Burnham
    • Best Vacuum Cleaners (2026): Cordless Vacuums, Robot Vacuums, Dysons
    • How AI is Changing Linux VPS Security for Businesses
    • These near-mint ASUS Chromebook refurbs are only $145
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Thursday, July 30
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Critical Ruflo Flaw Lets Attackers Spawn Rogue AI Swarms 

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKJuly 30, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Unauthenticated attackers could exploit a critical-severity vulnerability in the open source AI agent orchestration platform Ruflo to execute commands inside the container, Noma Labs security researchers warn.

    A popular automation assistant with over 67,000 GitHub stars, Ruflo (formerly Claude Flow) comes with a multi-model AI chat interface, agent swarms, persistent memory, and built-in Model Context Protocol (MCP) tool calling.

    Ruflo allows organizations to use AI applications, courtesy of agent swarms (support for coordinating up to 100 agents on shared enterprise-grade tasks), long-term memory enabling agents to recall past interactions, and an integrated MCP server enabling agents to execute various tasks.

    “The bridge exposes 233 tools covering shell access, database operations, agent management, and memory storage, making it the single point through which every agent action flows. Because the MCP Bridge requires direct access to the underlying system resources to execute these commands, it creates a high-stakes security boundary,” Noma explains.

    Tracked as CVE-2026-59726 (CVSS score of 10/10), the security defect was found in the MCP bridge in ruflo/docker-compose.yml, which exposed the POST /mcp endpoint without authentication.

    Because in default docker-compose deployments the bridge and MongoDB were bound to all interfaces, an unauthenticated attacker could invoke terminal_execute to run commands inside the bridge container, Ruflo’s advisory reads.

    Advertisement. Scroll to continue reading.

    Successful exploitation of the bug could allow the attacker to gain shell access as node, read provider API keys, spawn swarms on the victim’s keys, and inject poison patterns into the AgentDB learning store to tamper with the AI outputs for all users.

    According to Noma, which named the bug RufRoot, the root cause is that, in self-hosted deployments, the docker-compose.yml binds port 3001 to 0.0.0.0 by default, exposing all network-reachable instances to exploitation without authentication.

    “The MCP Bridge isn’t a random auxiliary debug interface; rather, it is Ruflo’s central nervous system. Every tool call, every agent action, every memory operation goes through the MCP Bridge. Mistakenly giving unauthenticated access to the MCP Bridge means giving unauthenticated access to everything,” Noma explains.

    With a single HTTP request targeting ruflo__terminal_execute, an attacker could take over the agent swarm, because the command would run as the container’s node user, providing access to all accessible assets without further escalation.

    “Once you have command execution, achieving full compromise is just chaining more requests to the same endpoint,” Noma explains.

    An attacker could exploit the vulnerability for reconnaissance, remote code execution (RCE), API key and conversation theft, spawning attacker-controlled agent swarms, poisoning the learning pipeline to produce attacker-influenced output, deploying persistent backdoors, and clearing shell history to remove traces.

    The vulnerability was patched in Ruflo version 3.16.3. The fix addresses all attack vectors, and Ruflo’s maintainers published remediation steps for users with exposed instances.

    Related: Chrome 151 Patches 370 Vulnerabilities

    Related: Cisco Secure FMC Zero-Day Exploited in the Wild

    Related: JFrog Zero-Days Exploited in OpenAI-Hugging Face Hack

    Related: Critical Arista VeloCloud Orchestrator Vulnerability Exploited as Zero-Day

    Attackers critical Flaw lets rogue Ruflo Spawn Swarms
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    These near-mint ASUS Chromebook refurbs are only $145

    Semiconductor Firm Analog Devices Discloses Data Breach

    Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation

    Windows 11 KB5101684 update released with 42 changes and fixes

    Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet

    Your AI Agents Are Guessing at Scale: Permissions Decide the Damage

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Posts claim Kim Jong Un demanded firing squad for Epstein associates. There’s no proof

    July 30, 2026

    Thousands evacuated in Crete but Spanish PM ends wildfire emergency

    July 30, 2026

    Tusk: ‘Everything indicates’ Russian cruise missile hit Poland

    July 30, 2026

    Only the Middle East crisis is preventing a drop in UK interest rates | Interest rates

    July 30, 2026
    Latest Posts

    Who’s in Andy Burnham’s new Labour cabinet?

    July 22, 2026

    Streeting apologises after early prisoner release comments heard on mic

    July 22, 2026

    Mehr Risikokapital, mehr Rüstung – Reiches Start-up-Plan – POLITICO

    July 22, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Posts claim Kim Jong Un demanded firing squad for Epstein associates. There’s no proof

    July 30, 2026

    Thousands evacuated in Crete but Spanish PM ends wildfire emergency

    July 30, 2026

    Tusk: ‘Everything indicates’ Russian cruise missile hit Poland

    July 30, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.