< ciso
brief />
Tag Banner

All news with #langgraph tag

6 articles

Agentic AI Enhances Operational Resilience in Banking

๐Ÿค– Deutsche Bank partnered with Google Cloud to build an agentic AI-driven resilience platform that modernizes regulatory tabletop exercises and incident analysis. The platform ingests architecture, logs, data flows, and telemetry to generate context-aware scenarios, audit-ready evidence, and structured session records. Using Gemini Enterprise Agent Platform, LangGraph, and Google ADK, the bank achieves both deterministic, traceable execution and adaptive investigation. This approach supports continuous, regulator-aligned resilience across complex, distributed systems.
read more โ†’

Researchers warn guardrails can enable AI DoS attacks

๐Ÿ›ก๏ธ New research shows that reasoning-based AI agent guardrails can be weaponized into denial-of-service vectors by a single poisoned document that traps safety systems in extended thinking loops. The study, from the Hong Kong University of Science and Technology and collaborators, demonstrated large slowdowns across four agent frameworks, with LangGraph suffering the worst impact. The work highlights a tradeoff where stronger guardrail reasoning increases resource use and introduces concentration risk for shared governance.
read more โ†’

Critical LangGraph flaw chain risks remote code execution

๐Ÿ”’ Researchers disclosed three patched vulnerabilities in LangGraph, including a critical SQL injection and unsafe deserialization chain that could enable remote code execution in self-hosted deployments. LangGraph is an open-source framework from LangChain for building stateful, multi-agent AI applications. Check Point and researcher Yarden Porat reported the issues, which affect SQLite and Redis checkpointers but not LangChain's managed LangSmith service.
read more โ†’

Critical LangGraph Vulnerabilities Put AI Agents at Risk

๐Ÿ”’ Check Point Research discovered a critical vulnerability chain in LangGraph, an open-source AI agent framework with ~46.5M monthly downloads, that can lead to full remote code execution. The issue centers on the checkpointer persistence layer where an SQL injection in get_state_history() can be chained with a msgpack deserialization flaw to execute attacker-controlled code. Three CVEs were assigned and patched; affected teams should upgrade and place authentication and network controls in front of self-hosted deployments.
read more โ†’

LangChain and LangGraph Flaws Expose Files and Secrets

๐Ÿ”’ Researchers disclosed three vulnerabilities in LangChain and LangGraph that can expose filesystem files, environment secrets, and conversation history. The flaws โ€” a path traversal, insecure deserialization, and an SQL injection โ€” provide independent attack paths enabling exfiltration of Docker configs, API keys, and stored chats. Patches are available for the affected packages and organizations are urged to update immediately and audit prompt templates, deserialization paths, and checkpoint metadata.
read more โ†’

Amazon CloudWatch Adds Generative AI Observability

๐Ÿ” Amazon CloudWatch is generally available with Generative AI Observability, providing end-to-end telemetry for AI applications and AgentCore-managed agents. It expands monitoring beyond model runtime to include Built-in Tools, Gateways, Memory, and Identity, surfacing latency, token usage, errors, and performance across components. The capability integrates with orchestration frameworks like LangChain, LangGraph, and Strands Agents, and works with existing CloudWatch features and pricing for underlying telemetry.
read more โ†’