Sam's News — security — 2026-09-01¶
Security¶
8.5 Critical JFrog Artifactory authentication bypass vulnerability actively exploited in the wild¶
Attackers are actively exploiting CVE-2026-82329, a critical authentication bypass flaw in JFrog Artifactory (CVSS 9.8), to mint admin tokens just days after the patch was disclosed.
- CVE-2026-82329 disclosed August 28, 2026; actively exploited by September 1
- Flaw allows unauthenticated attackers to obtain admin privileges
- Affects Artifactory, widely used for managing software artifacts and packages
- Patches released for versions 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, 7.161.20
- Cloud instances auto-patched; self-hosted customers must manually update
Sources: SecurityWeek AI Web Searched, The Hacker News RSS
8.5 Hackers exploit critical Langflow vulnerability CVE-2024-0768¶
Threat actors are exploiting an unauthenticated remote code execution vulnerability (CVE-2026-0768) in Langflow to steal API credentials, tokens, and AWS keys.
- CVSS 9.8 critical severity in all Langflow releases up to 1.4.2
- Affects custom component editor; no authentication required for RCE
- Over 360 exploitation attempts against UK honeypots by early September 2026
- Publicly disclosed January 2026; reported to ZDI July 2025
- At least 11 additional Langflow CVEs exploited in wild by September 2026
Sources: SecurityWeek AI Web Searched, BleepingComputer RSS
8 13 malicious Packagist packages target iPhones to steal cryptocurrency wallet seeds¶
Researchers discovered 13 malicious Composer packages on Packagist designed to inject spyware targeting unpatched iPhones for cryptocurrency wallet theft. The exploit chain affects iOS 18.4–18.6.x, ultimately harvesting keychains, passwords, browser data, and cryptocurrency wallet seeds from devices running vulnerable versions.
- 13 malicious packages across 5 vendor namespaces on Packagist
- Targets unpatched iOS 18.4–18.6.x devices running WebKit vulnerabilities
- Exploits CVE-2025-31277 and CVE-2025-43529 to reach kernel, gain read/write access
- August 12, 2026 variant adds cryptocurrency wallet seed stealer for 7 wallets
- Steals keychains, Wi-Fi passwords, SMS, address book, browser cookies, location history
Sources: The Hacker News AI Web Searched
8 Nearly 22,000 unpatched Microsoft Exchange servers vulnerable to authentication bypass¶
Approximately 22,000 Microsoft Exchange servers remain exposed online without security patches for a high-severity authentication bypass vulnerability allowing mailbox hijacking.
Sources: BleepingComputer RSS
7.5 Hackers deliver malicious Virtualizor updates via BGP hijacking attack¶
Attackers hijacked BGP routing to redirect Virtualizor VPS management software update requests to malicious servers.
Sources: BleepingComputer RSS
7.5 Fire Ant hacking campaign exploited compromised Cisco routers for widespread attacks¶
Researchers uncovered a China-based hacking campaign called Fire Ant that compromised Cisco routers to launch broader attacks and gain persistent network access. The group, which overlaps with UNC3886, exploited infrastructure relationships to access critical systems while evading detection.
- Campaign targeted Cisco IOS XR routers for persistent access
- Fire Ant overlaps with Google Mandiant's UNC3886 designation
- Active from at least 2022 through 2026
- Malware modified routers and monitored organizational traffic
- Targeted TACACS authentication servers and concealed activity via log deletion
Sources: The Record AI Web Searched
7 Russia-aligned UAC-0099 deploys GuardBreaker malware prompt injection against Ukraine¶
Russian-aligned threat actor UAC-0099 deployed GuardBreaker, a prompt injection technique embedding adversarial text in malware code to disable AI-assisted analysis. The tactic—inserting fake nuclear weapon instructions in Visual Basic scripts—triggers LLM safety mechanisms to prevent code analysis and facilitate MATCHBOIL loader delivery.
- GuardBreaker embeds prompt injection text in malware to disrupt AI analysis
- UAC-0099 targeted Ukraine with GuardBreaker-modified VBS scripts
- Technique: fake nuclear/biological weapon requests trigger LLM refusal state
- GuardBreaker VBS part of toolset distributing MATCHBOIL C# loader
- Follows UAC-0099's July 2026 malicious Notepad++ plugin campaign delivering MATCHBOIL
Sources: The Hacker News AI Web Searched
7 Berlin ransomware attack: Rhysida exploits 7-day detection gap to steal critical infrastructure data¶
The Rhysida ransomware gang stole critical infrastructure data from Berlin during a seven-day window before the attack was detected and isolated.
Sources: Tech Times RSS
7 Novocure data breach exposes information of 1,400+ cancer patients¶
Healthtech company Novocure confirmed a mid-August cyberattack compromised employee and patient data affecting over 1,400 U.S. cancer patients.
Sources: BleepingComputer RSS
Data Breach¶
7.5 Aesto Health data breach impacts 9.5 million¶
Healthcare technology company Aesto Health disclosed a breach affecting 9.5 million individuals, including personal and health data exposed through unauthorized AWS infrastructure access. Hackers exfiltrated data between December 2–18, 2025, with the compromise discovered the same month and formally reported to HHS on or before September 1, 2026.
- Aesto Health breach affected 9,540,683 individuals
- Unauthorized access to Amazon Web Services infrastructure
- Data exfiltrated December 2–18, 2025; discovery December 18, 2025
- Compromised data includes names, Social Security numbers, driver's licenses, medical records, insurance info
- At least two dozen healthcare provider clients across several states affected
Sources: SecurityWeek AI Web Searched