Attackers began exploiting a critical flaw in Langflow, an open-source tool for building AI workflows. The bug scores 9.8 out of 10 and lets a stranger run code as root without logging in. VulnCheck counted over 360 attempts by Monday, most of them hunting OpenAI and AWS keys.