Skip to content

Sam's News — security — 2026-09-01

Security

8.5 Critical JFrog Artifactory authentication bypass vulnerability actively exploited in the wild

Attackers are actively exploiting CVE-2026-82329, a critical authentication bypass flaw in JFrog Artifactory (CVSS 9.8), to mint admin tokens just days after the patch was disclosed.

  • CVE-2026-82329 disclosed August 28, 2026; actively exploited by September 1
  • Flaw allows unauthenticated attackers to obtain admin privileges
  • Affects Artifactory, widely used for managing software artifacts and packages
  • Patches released for versions 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, 7.161.20
  • Cloud instances auto-patched; self-hosted customers must manually update

Sources: SecurityWeek AI Web Searched, The Hacker News RSS

8.5 Hackers exploit critical Langflow vulnerability CVE-2024-0768

Threat actors are exploiting an unauthenticated remote code execution vulnerability (CVE-2026-0768) in Langflow to steal API credentials, tokens, and AWS keys.

  • CVSS 9.8 critical severity in all Langflow releases up to 1.4.2
  • Affects custom component editor; no authentication required for RCE
  • Over 360 exploitation attempts against UK honeypots by early September 2026
  • Publicly disclosed January 2026; reported to ZDI July 2025
  • At least 11 additional Langflow CVEs exploited in wild by September 2026

Sources: SecurityWeek AI Web Searched, BleepingComputer RSS

8 13 malicious Packagist packages target iPhones to steal cryptocurrency wallet seeds

Researchers discovered 13 malicious Composer packages on Packagist designed to inject spyware targeting unpatched iPhones for cryptocurrency wallet theft. The exploit chain affects iOS 18.4–18.6.x, ultimately harvesting keychains, passwords, browser data, and cryptocurrency wallet seeds from devices running vulnerable versions.

  • 13 malicious packages across 5 vendor namespaces on Packagist
  • Targets unpatched iOS 18.4–18.6.x devices running WebKit vulnerabilities
  • Exploits CVE-2025-31277 and CVE-2025-43529 to reach kernel, gain read/write access
  • August 12, 2026 variant adds cryptocurrency wallet seed stealer for 7 wallets
  • Steals keychains, Wi-Fi passwords, SMS, address book, browser cookies, location history

Sources: The Hacker News AI Web Searched

8 Nearly 22,000 unpatched Microsoft Exchange servers vulnerable to authentication bypass

Approximately 22,000 Microsoft Exchange servers remain exposed online without security patches for a high-severity authentication bypass vulnerability allowing mailbox hijacking.

Sources: BleepingComputer RSS

7.5 Hackers deliver malicious Virtualizor updates via BGP hijacking attack

Attackers hijacked BGP routing to redirect Virtualizor VPS management software update requests to malicious servers.

Sources: BleepingComputer RSS

7.5 Fire Ant hacking campaign exploited compromised Cisco routers for widespread attacks

Researchers uncovered a China-based hacking campaign called Fire Ant that compromised Cisco routers to launch broader attacks and gain persistent network access. The group, which overlaps with UNC3886, exploited infrastructure relationships to access critical systems while evading detection.

  • Campaign targeted Cisco IOS XR routers for persistent access
  • Fire Ant overlaps with Google Mandiant's UNC3886 designation
  • Active from at least 2022 through 2026
  • Malware modified routers and monitored organizational traffic
  • Targeted TACACS authentication servers and concealed activity via log deletion

Sources: The Record AI Web Searched

7 Russia-aligned UAC-0099 deploys GuardBreaker malware prompt injection against Ukraine

Russian-aligned threat actor UAC-0099 deployed GuardBreaker, a prompt injection technique embedding adversarial text in malware code to disable AI-assisted analysis. The tactic—inserting fake nuclear weapon instructions in Visual Basic scripts—triggers LLM safety mechanisms to prevent code analysis and facilitate MATCHBOIL loader delivery.

  • GuardBreaker embeds prompt injection text in malware to disrupt AI analysis
  • UAC-0099 targeted Ukraine with GuardBreaker-modified VBS scripts
  • Technique: fake nuclear/biological weapon requests trigger LLM refusal state
  • GuardBreaker VBS part of toolset distributing MATCHBOIL C# loader
  • Follows UAC-0099's July 2026 malicious Notepad++ plugin campaign delivering MATCHBOIL

Sources: The Hacker News AI Web Searched

7 Berlin ransomware attack: Rhysida exploits 7-day detection gap to steal critical infrastructure data

The Rhysida ransomware gang stole critical infrastructure data from Berlin during a seven-day window before the attack was detected and isolated.

Sources: Tech Times RSS

7 Novocure data breach exposes information of 1,400+ cancer patients

Healthtech company Novocure confirmed a mid-August cyberattack compromised employee and patient data affecting over 1,400 U.S. cancer patients.

Sources: BleepingComputer RSS

Data Breach

7.5 Aesto Health data breach impacts 9.5 million

Healthcare technology company Aesto Health disclosed a breach affecting 9.5 million individuals, including personal and health data exposed through unauthorized AWS infrastructure access. Hackers exfiltrated data between December 2–18, 2025, with the compromise discovered the same month and formally reported to HHS on or before September 1, 2026.

  • Aesto Health breach affected 9,540,683 individuals
  • Unauthorized access to Amazon Web Services infrastructure
  • Data exfiltrated December 2–18, 2025; discovery December 18, 2025
  • Compromised data includes names, Social Security numbers, driver's licenses, medical records, insurance info
  • At least two dozen healthcare provider clients across several states affected

Sources: SecurityWeek AI Web Searched