360 AI Agent Finds 13 Zero-Day Flaws in Flowise
Chinese cybersecurity firm 360 has demonstrated the potency of AI-driven penetration testing by deploying an autonomous vulnerability mining agent that uncovered 13 zero-day flaws in Flowise, a popular open-source platform for building AI applications, with 8 confirmed and some already patched—underscoring the urgent need for automated security auditing as enterprise AI adoption accelerates.
The discovered vulnerabilities specifically target Flowise's authentication, permission control, and cross-organization access boundaries, revealing three distinct failure categories: data boundary failures that allow unauthorized data leakage; workspace and organization boundary failures enabling users to breach tenant isolation; and enterprise governance failures that compromise compliance and audit trails. 360 classified these as systemic architectural weaknesses rather than isolated coding errors.
Flowise, which has garnered over 53,000 GitHub stars and was recently acquired by Workday to power HR and finance AI agents, exposes more than 30,000 public instances worldwide. The sheer scale of exposed endpoints amplifies the risk, particularly given that many instances are deployed without proper security hardening. 360's analysis validates a methodical engineering approach combining multi-agent collaboration, domain expertise from security veterans, and automated verification to unearth deep blind spots in complex permission chains.
The incident carries a stark warning for the broader AI ecosystem: manual security audits can no longer keep pace with the rapid proliferation of open-source AI tooling. To defend against similar supply-chain scale attacks, organizations must adopt automated, intelligent security auditing that mirrors the speed of AI development. 360's agent demonstrates that AI itself can be weaponized for defense—but only if defenders deploy comparable autonomous systems to close the gap.