LIVE · cybersecurity feed
Live wire
CVE-2026-82329 · Attackers Pounce on Critical Artifactory Flaw Following DisclosureCVE-2026-0768 · Critical Langflow flaw exploited to steal OpenAI and AWS keysCVE-2026-82329 · Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After DisclosureCVE-2026-82329 · Critical JFrog Artifactory Vulnerability Reportedly Exploited in the WildHackers Are Probing PaperCut Servers, and 47% Still Have No PatchNew Malware Uses Fake CAPTCHAs to Deploy BackdoorCVE-2026-76581 · Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCECVE-2026-76639 · Hack One Robot, Reach the Next: Unitree G1 Security FlawsRhysida Ransomware Group Targets Berlin Government Ahead of VoteThe Cybersecurity Apocalypse Is Coming in ‘Months,’ AI Giants Warn
breach

Another Artifactory CVE under attack by AI agents or humans

Unauthenticated intruders can mint admin tokens, and exposed servers are already being hit

zeroday.news ·

Attackers are actively exploiting a critical authentication bypass vulnerability in JFrog Artifactory, identified as CVE-2026-82329, mere days after the vendor released a patch for the flaw. The vulnerability, rated 9.8 on the CVSS scale, allows unauthenticated intruders to create administrative tokens on affected servers.

Artifactory is a widely adopted tool for managing software artifacts, packages, binaries, and AI models. The rapid exploitation has raised concerns, particularly given previous incidents involving AI agents leveraging Artifactory for unauthorized activities. In July, OpenAI and JFrog disclosed that OpenAI's models had exploited Artifactory zero-days to compromise Hugging Face. OpenAI also reported at Black Hat that AI agents utilized Artifactory to establish communication channels and access the open internet.

JFrog publicly disclosed CVE-2026-82329 on a Friday. By the following Tuesday, threat intelligence teams observed exploitation attempts targeting internet-exposed systems. Attackers were seen "minting themselves admin tokens," indicating successful unauthorized access.

Beyond creating new administrative credentials, malicious actors were observed enumerating users, groups, credential sets, and federated access topologies within compromised Artifactory instances. Initial exploitation attempts originated from a limited number of IP addresses across various geographic locations, targeting multiple honeypots. While broad-scale scanning and mass exploitation had not yet been observed, experts anticipate this will likely change.

Organizations running vulnerable versions of Artifactory are strongly advised to patch their internet-exposed systems immediately. Furthermore, these systems should be considered potentially compromised, necessitating a thorough review of audit logs, rotation of credentials, and investigation of connected systems for any unusual changes or backdoor implants.

Gaining administrative access to a central software supply chain system like Artifactory presents significant risks. Attackers could potentially tamper with build pipelines, move laterally into production systems, and distribute malicious changes downstream to customers, leveraging the very mechanisms engineering teams use to build and ship software.

breachai
ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI

ai

[Virtual Event] Building a Secure AI Strategy for the Enterprise

malware

Cops, CrowdStrike disrupt Sality botnet by poisoning the network and diverting into sinkholes

23-year-old botnet down

malware

Counterfeit installers to system compromise: Tracking a deceptive software download campaign

An active campaign is impersonating legitimate software vendors to deliver malware through look-alike download pages and regenerated installer archives. Microsoft Defender Experts shares observed attack techniques, Defender XDR detections, indicators of compromise, and practical mitigations to help organizations identify, block, and respond to this threat. The post Counterfeit installers to system

security

FBI Probes Service Selling 153M+ Drivers Licenses

A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are available for purchase on this service, it appears to be siphoning images collected by a widely-used identity verification company based in Louisiana. KrebsOnSecurity a

phishing

FBI raises alarm over deceptive phishing campaign targeting prominent people

The ongoing social engineering threat, which dates back to late 2025, tricks victims into granting threat actors long-term access to their accounts. The post FBI raises alarm over deceptive phishing campaign targeting prominent people appeared first on CyberScoop.