Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7

Attackers exploit a critical JFrog Artifactory flaw to mint admin tokens

Days after disclosure, attackers are exploiting a critical authentication-bypass flaw in JFrog Artifactory, the widely used repository manager for binaries, packages, containers, and build artifacts. Tracked as CVE-2026-82329 and scored 9.8, the flaw lets an unauthenticated attacker with network access gain administrative privileges under Artifactory's default configuration. Researchers at watchTowr observed exploitation beginning September 1, with attackers minting admin tokens for themselves and enumerating users, groups, and credentials. Because Artifactory sits at the center of software supply chains and CI/CD pipelines, admin access lets attackers tamper with build pipelines, poison trusted dependencies, and push malicious code downstream to customers. JFrog patched it in version 7.161.20 on August 28.

Check
Patch self-managed JFrog Artifactory to 7.161.20 or later immediately, prioritizing internet-exposed instances, then inspect audit logs for unexpected admin tokens, user enumeration, and any changes to hosted artifacts.
Affected
Organizations running self-managed JFrog Artifactory in default configuration (CVE-2026-82329); an unauthenticated attacker with network access can gain admin, mint tokens, harvest credentials, and tamper with the supply chain, and exploitation is active.
Fix
Patch now, rotate Artifactory credentials and tokens, review hosted packages and build pipelines for tampering, restrict network exposure of the service, and treat any exposed unpatched instance as a supply-chain compromise.

ClickFix campaign hides its command server on the Polygon blockchain

Researchers at GuidePoint found a ClickFix campaign that compromised at least 31 organizations' websites and abuses the Polygon blockchain to run its command-and-control, a technique called EtherHiding. Visitors arriving from search engines hit a fake human-verification prompt that abuses Cloudflare's overlay and tells them to paste a command, which installs a persistent backdoor. Instead of a fixed server address that defenders can block, the backdoor fetches its current instructions from a Polygon smart contract every minute, giving the attacker a censorship-resistant, easily updated address book. This breaks the usual defense of blocking a hardcoded command server, so defenders should focus on behavior and audit their public-facing sites.

Check
Teach users that no verification prompt should ask them to paste commands, audit public-facing websites for injected scripts, and hunt for backdoors that resolve command servers through blockchain queries.
Affected
Organizations whose websites are compromised to serve the fake verification lure, and users tricked into running the pasted command; the resulting backdoor persists and pulls updatable instructions from the blockchain.
Fix
Detect on behavior rather than static addresses, block or flag outbound blockchain-resolution queries from endpoints, monitor for domain-generation patterns, continuously audit websites for injected code, and train users against paste-a-command verification tricks.

Researcher drops unpatched zero-days that turn Kaspersky and Avast against the system

A researcher known as Chaotic Eclipse, or Nightmare Eclipse, publicly released two unpatched privilege-escalation zero-day exploits targeting security software, without coordinating with the vendors. One, called HardBreacher, targets Kaspersky Endpoint Security and can disrupt the antivirus and its file-access controls while creating a system-level file. The other, PrettyPrague, escapes the Avast sandbox to dump the Windows account database and spawn a SYSTEM-level shell, and reportedly works on fully patched Avast and Windows 11. The researcher suspects it may also affect other Gen Digital products like AVG and Norton. Because there are no CVEs or patches yet, endpoints are exposed, and security tools' high privileges make them valuable targets.

Check
Track these public exploits closely since no patch exists, monitor endpoints for antivirus tampering, unexpected SYSTEM shells, and access to the Windows account database, and press affected vendors for fixes.
Affected
Windows systems running Kaspersky Endpoint Security or Avast and other Gen Digital antivirus products; the released exploits can escalate a local user to SYSTEM, dump credentials, and disable protection, with no patch.
Fix
Watch for these exploits moving from proof-of-concept to real attacks, restrict local access, monitor for credential-database dumping and security-tool interference, apply vendor patches as soon as they ship, and add compensating detection.

Malware carries a hidden prompt to derail AI-assisted analysis

ESET found that a Russia-aligned group planted a prompt inside a malicious script designed to trip an AI system's safety filters and disrupt AI-assisted malware analysis. The technique, dubbed GuardBreaker, embeds text about a sensitive topic so that a language model reviewing the code refuses or derails instead of analyzing it. The script itself installs a loader the group uses to deliver further payloads. It is not isolated: earlier in 2026, malicious packages in supply-chain campaigns used similar anti-analysis tricks against systems leaning on a language model for triage. The lesson is that automated AI triage can be manipulated by the code it inspects, so human review remains essential.

Check
If you use language models to triage code or malware, assume attackers will manipulate them, and keep human analysts and traditional sandboxing in the loop rather than trusting AI output alone.
Affected
Security workflows relying on language models for first-pass code or malware triage; attackers embed prompts in samples to trigger safety refusals or misdirection, causing the AI to skip or misjudge malicious code.
Fix
Treat AI triage output as manipulable, isolate the model from acting on embedded instructions, combine it with signature and behavioral analysis and human review, and test pipelines against prompt-injection samples.

Malicious Packagist themes attack unpatched iPhones to steal wallet seed phrases

Researchers found thirteen malicious packages on Packagist, the PHP Composer registry, posing as content-management themes that inject JavaScript into the sites that use them. On visitors' devices the script runs gambling and ad-fraud redirects, and on iPhones it loads a WebKit exploit chain that, against unpatched devices, installs spyware and steals cryptocurrency wallet seed phrases. The packages span several vendor names and extend a campaign first seen in March that abused similar theme packages and attacker-hosted infrastructure. It is a reminder that a compromised server-side dependency can become a delivery system for attacks against every visitor, including mobile users, not just the server it runs on.

Check
Audit PHP Composer and Packagist dependencies, especially themes, for untrusted or recently changed packages, remove suspicious ones, and make sure devices, including iPhones, are patched against known WebKit flaws.
Affected
Websites pulling the malicious Composer themes and their visitors; injected JavaScript redirects users and, on unpatched iPhones, chains WebKit exploits to install spyware and steal cryptocurrency wallet seed phrases from victims.
Fix
Vet and pin server-side dependencies, monitor sites for injected scripts and unexpected redirects, keep client devices patched, use content security policies to limit injected code, and treat theme packages as supply-chain risk.

Aesto Health breach exposes health and identity data of 9.5 million people

Aesto Health, a healthcare technology company that handles data migration, records exchange, and archiving for medical providers, disclosed that a breach of its Amazon Web Services infrastructure exposed the personal and health information of more than 9.5 million people. Attackers accessed the environment in December 2025, and the company later confirmed they took names, Social Security and driver's license numbers, dates of birth, financial account numbers, and detailed medical and insurance information. Because Aesto is a vendor serving many providers, the single breach cascades to roughly two dozen healthcare clients. It is the second-largest confirmed US healthcare breach reported this year, and the data enables identity theft and targeted fraud.

Check
If you are a provider using Aesto Health or a patient of one, watch for breach notifications, monitor medical, insurance, and financial statements, and treat health-themed phishing referencing real details with suspicion.
Affected
More than 9.5 million patients across about two dozen providers served by Aesto Health; exposed names, Social Security numbers, financial accounts, and medical records support identity theft, insurance fraud, and targeted phishing.
Fix
Affected people should monitor accounts and consider credit protection; organizations should secure cloud infrastructure, minimize retained data, encrypt records, and vet the security of data-handling vendors whose breach would cascade.

Attackers exploit critical Langflow and Rails flaws to harvest secrets

VulnCheck reported active exploitation of two critical flaws, one in the AI workflow builder Langflow and one in Ruby on Rails. The Langflow bug, CVE-2026-0768, scored 9.8, lets an attacker run arbitrary Python code as root through improper input validation. The Rails bug, CVE-2026-66066 and nicknamed KindaRails2Shell at 9.5, lets an unauthenticated attacker read arbitrary files by uploading a crafted image that exploits a mismatch between Active Storage and the libvips image library, leaking secrets like the Rails master key and cloud credentials and ultimately enabling code execution. Detections jumped from about 50 to 360 within a day, with attackers querying environment variables for OpenAI and AWS keys and probing SSH access.

Check
Patch Langflow and Ruby on Rails to fixed versions now, and rotate any secrets an attacker could have read, including the Rails master key, database passwords, cloud credentials, and API keys.
Affected
Internet-facing Langflow servers (CVE-2026-0768) and Rails apps using Active Storage with libvips (CVE-2026-66066); attackers can run code as root or read files leaking the master key, cloud credentials, and API tokens.
Fix
Update both immediately, rotate exposed secrets, restrict internet exposure of Langflow, review logs for environment-variable probing and image-upload abuse, and treat any exposed instance as potentially credential-compromised.

Aurora ransomware crew used an AI coding agent for hands-on network intrusion

Researchers at CloudSEK and Gambit Security found that operators of the Russian-speaking Aurora ransomware used the agentic coding assistant Cursor to help break into around ten victim networks. After obtaining valid credentials or a route in, the operator directed the agent to run reconnaissance, assess privileges, scan internally, and attempt exploitation, often revising commands several times before they worked, which shows the human stayed in control and used the AI as an assistant rather than an autonomous attacker. The group also built a Linux encryptor that force-terminates VMware ESXi guest virtual machines to unlock their disk files before encrypting them. Initial access in one case came through help desk impersonation phone calls.

Check
Assume attackers now use agentic AI to accelerate hands-on intrusion, and focus detection on the resulting behavior: unusual internal scanning, privilege checks, log clearing, Defender being disabled, and mass ESXi activity.
Affected
Organizations facing hands-on ransomware intrusions, including VMware ESXi environments; operators use AI assistants to speed reconnaissance and exploitation after entry, and the ESXi encryptor kills guests to encrypt their disks.
Fix
Harden help desk verification against impersonation calls, protect ESXi management interfaces, restrict lateral movement, alert on Defender tampering and log clearing, and keep offline backups, since AI mainly speeds familiar steps.

Stolen AI API key from an exposed app burned through 600,000 dollars in credits

The AI evaluation nonprofit METR disclosed that attackers stole a model-provider API key and ran up about 600,000 dollars worth of inference credits over three weeks. The key sat on a researcher's personal cloud instance that was meant to be protected by a Google login but, due to a fail-open authentication bug in a quickly built app, was actually publicly reachable. After finding it, the attacker prompted the AI agent running there to reveal its provider API key, added an SSH key for persistence, and consumed credits on public models. The abuse went unnoticed for a while because METR routinely runs high-token evaluations and had no spending caps on the key.

Check
Keep provider API keys off personal and non-organizational infrastructure, add spend caps and usage alerts to every key, and make sure agents cannot be prompted into revealing the credentials they hold.
Affected
Organizations with AI provider API keys on loosely protected or personal infrastructure; a stolen key with no spending cap can rack up costly inference, and exposed agents may leak keys when prompted.
Fix
Store keys in a secrets manager, scope and cap them, monitor for anomalous token spend, avoid embedding retrievable keys in agent environments, and verify quickly built apps fail closed, not open.

ValleyRAT backdoor hides in signed adware users add to antivirus exclusions

Kaspersky reported that the group known as Silver Fox is spreading the ValleyRAT backdoor, also called Winos 4.0, hidden inside a genuine but signed Chinese adware application called QN Wallpaper. By side-loading a malicious library through the trusted, signed program, the malware runs inside a process users are likely to have added to their antivirus exclusion lists, and it disables Windows Defender. Once active, it gives the operator full control, capturing keystrokes, clipboard contents, and screenshots and loading further modules. Kaspersky recorded more than 100,000 detections of ValleyRAT this year, mostly in China and India, and warns that adware and affiliate networks can be far more dangerous than they look.

Check
Warn users not to install questionable or adware-bundled software and never to add it to antivirus exclusion lists, and hunt for signed processes side-loading unexpected libraries or disabling Defender.
Affected
Windows users who install low-reputation adware and exclude it from antivirus scanning; the signed host process side-loads ValleyRAT, which disables Defender and gives attackers full remote control of the machine.
Fix
Block low-reputation and adware software through application control, avoid broad antivirus exclusions, monitor for DLL sideloading from signed processes and Defender being disabled, and treat trusted-but-questionable software as a real threat vector.