Days after disclosure, attackers are exploiting a critical authentication-bypass flaw in JFrog Artifactory, the widely used repository manager for binaries, packages, containers, and build artifacts. Tracked as CVE-2026-82329 and scored 9.8, the flaw lets an unauthenticated attacker with network access gain administrative privileges under Artifactory's default configuration. Researchers at watchTowr observed exploitation beginning September 1, with attackers minting admin tokens for themselves and enumerating users, groups, and credentials. Because Artifactory sits at the center of software supply chains and CI/CD pipelines, admin access lets attackers tamper with build pipelines, poison trusted dependencies, and push malicious code downstream to customers. JFrog patched it in version 7.161.20 on August 28.
Researchers at GuidePoint found a ClickFix campaign that compromised at least 31 organizations' websites and abuses the Polygon blockchain to run its command-and-control, a technique called EtherHiding. Visitors arriving from search engines hit a fake human-verification prompt that abuses Cloudflare's overlay and tells them to paste a command, which installs a persistent backdoor. Instead of a fixed server address that defenders can block, the backdoor fetches its current instructions from a Polygon smart contract every minute, giving the attacker a censorship-resistant, easily updated address book. This breaks the usual defense of blocking a hardcoded command server, so defenders should focus on behavior and audit their public-facing sites.
A researcher known as Chaotic Eclipse, or Nightmare Eclipse, publicly released two unpatched privilege-escalation zero-day exploits targeting security software, without coordinating with the vendors. One, called HardBreacher, targets Kaspersky Endpoint Security and can disrupt the antivirus and its file-access controls while creating a system-level file. The other, PrettyPrague, escapes the Avast sandbox to dump the Windows account database and spawn a SYSTEM-level shell, and reportedly works on fully patched Avast and Windows 11. The researcher suspects it may also affect other Gen Digital products like AVG and Norton. Because there are no CVEs or patches yet, endpoints are exposed, and security tools' high privileges make them valuable targets.
ESET found that a Russia-aligned group planted a prompt inside a malicious script designed to trip an AI system's safety filters and disrupt AI-assisted malware analysis. The technique, dubbed GuardBreaker, embeds text about a sensitive topic so that a language model reviewing the code refuses or derails instead of analyzing it. The script itself installs a loader the group uses to deliver further payloads. It is not isolated: earlier in 2026, malicious packages in supply-chain campaigns used similar anti-analysis tricks against systems leaning on a language model for triage. The lesson is that automated AI triage can be manipulated by the code it inspects, so human review remains essential.
Researchers found thirteen malicious packages on Packagist, the PHP Composer registry, posing as content-management themes that inject JavaScript into the sites that use them. On visitors' devices the script runs gambling and ad-fraud redirects, and on iPhones it loads a WebKit exploit chain that, against unpatched devices, installs spyware and steals cryptocurrency wallet seed phrases. The packages span several vendor names and extend a campaign first seen in March that abused similar theme packages and attacker-hosted infrastructure. It is a reminder that a compromised server-side dependency can become a delivery system for attacks against every visitor, including mobile users, not just the server it runs on.
Aesto Health, a healthcare technology company that handles data migration, records exchange, and archiving for medical providers, disclosed that a breach of its Amazon Web Services infrastructure exposed the personal and health information of more than 9.5 million people. Attackers accessed the environment in December 2025, and the company later confirmed they took names, Social Security and driver's license numbers, dates of birth, financial account numbers, and detailed medical and insurance information. Because Aesto is a vendor serving many providers, the single breach cascades to roughly two dozen healthcare clients. It is the second-largest confirmed US healthcare breach reported this year, and the data enables identity theft and targeted fraud.
VulnCheck reported active exploitation of two critical flaws, one in the AI workflow builder Langflow and one in Ruby on Rails. The Langflow bug, CVE-2026-0768, scored 9.8, lets an attacker run arbitrary Python code as root through improper input validation. The Rails bug, CVE-2026-66066 and nicknamed KindaRails2Shell at 9.5, lets an unauthenticated attacker read arbitrary files by uploading a crafted image that exploits a mismatch between Active Storage and the libvips image library, leaking secrets like the Rails master key and cloud credentials and ultimately enabling code execution. Detections jumped from about 50 to 360 within a day, with attackers querying environment variables for OpenAI and AWS keys and probing SSH access.
Researchers at CloudSEK and Gambit Security found that operators of the Russian-speaking Aurora ransomware used the agentic coding assistant Cursor to help break into around ten victim networks. After obtaining valid credentials or a route in, the operator directed the agent to run reconnaissance, assess privileges, scan internally, and attempt exploitation, often revising commands several times before they worked, which shows the human stayed in control and used the AI as an assistant rather than an autonomous attacker. The group also built a Linux encryptor that force-terminates VMware ESXi guest virtual machines to unlock their disk files before encrypting them. Initial access in one case came through help desk impersonation phone calls.
The AI evaluation nonprofit METR disclosed that attackers stole a model-provider API key and ran up about 600,000 dollars worth of inference credits over three weeks. The key sat on a researcher's personal cloud instance that was meant to be protected by a Google login but, due to a fail-open authentication bug in a quickly built app, was actually publicly reachable. After finding it, the attacker prompted the AI agent running there to reveal its provider API key, added an SSH key for persistence, and consumed credits on public models. The abuse went unnoticed for a while because METR routinely runs high-token evaluations and had no spending caps on the key.
Kaspersky reported that the group known as Silver Fox is spreading the ValleyRAT backdoor, also called Winos 4.0, hidden inside a genuine but signed Chinese adware application called QN Wallpaper. By side-loading a malicious library through the trusted, signed program, the malware runs inside a process users are likely to have added to their antivirus exclusion lists, and it disables Windows Defender. Once active, it gives the operator full control, capturing keystrokes, clipboard contents, and screenshots and loading further modules. Kaspersky recorded more than 100,000 detections of ValleyRAT this year, mostly in China and India, and warns that adware and affiliate networks can be far more dangerous than they look.