JFrog Artifactory auth-bypass exploited within days of disclosure — attackers minting admin tokens
- What happened
- A critical authentication-bypass flaw in JFrog Access (which issues Artifactory credentials) lets an unauthenticated attacker forge a "phantom" join key and mint admin-level tokens; watchTowr confirmed in-the-wild exploitation used to enumerate users, groups, credentials, and federated access topologies just days after the patch landed.
- Affected
- Artifactory 7.111.4–7.111.21, 7.117.0–7.117.27, 7.125.0–7.125.19, 7.133.0–7.133.28, 7.146.0–7.146.36, and 7.161.0–7.161.19 (self-hosted instances without an additional join key configured).
- Exploitation
- actively exploited in the wild (watchTowr, reported via The Hacker News).
- Fix
- upgrade to 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, or 7.161.20.
- Check if you're exposed
- confirm an additional join key is configured; after patching, audit for unexpected admin tokens, review access logs for anomalous token-minting or enumeration of users/groups/credential sets, and rotate all credentials on internet-exposed instances.
Aurora ransomware affiliate caught using AI coding agent Cursor to plan intrusions — email-bombing/vishing was the way in
- What happened
- An exposed open directory belonging to a Russian-speaking Aurora ransomware affiliate revealed months of operational logs showing the actor using the Cursor AI coding assistant (running on Claude Sonnet) as an active planning tool during real intrusions against 20+ organizations across nine countries, with initial access via email-bombing followed by IT-helpdesk vishing calls.
- Affected
- No specific product vulnerability — this is a TTP/tooling exposure covering organizations targeted between April and July 2026, explicitly excluding CIS-region targets.
- Exploitation
- not a CVE — actively used in real-world ransomware operations (CloudSEK and Gambit Security research, reported via The Hacker News).
- Fix
- N/A (process/tooling issue) — harden helpdesk identity-verification procedures and add controls against email-bombing-triggered support calls.
- Check if you're exposed
- watch for the Windows encryptor sap.exe, Linux/ESXi encryptor encrypt.out, and the ESXi/vCenter discovery script esxi_finder.py; flag help-desk call volume spikes immediately following inbound email floods, and monitor for anomalous SMB/LDAP/WinRM/RDP/RPC lateral movement after a helpdesk-impersonation call.
Recommended deep-dive for this window
For the PaperCut NG/MF chain (CVE-2026-81578/CVE-2026-82078), now on CISA KEV with a Sept 14 deadline: what is the full scope of post-patch data-theft activity that Defused and others have observed — which threat actors are involved, what data types are being exfiltrated, and is this ransomware pre-positioning or pure espionage? Given PaperCut has withheld detailed IOCs while investigating, what detection logic (beyond the partial log-error strings and pc-app.exe monitoring already public) can defenders build now, and what does incomplete patching (Emergency Patch Release 1 vs. Release 2) mean for organizations that patched early but remain exposed?
PaperCut is the single most urgent, broadly-deployed item this window — it has a hard federal deadline, confirmed active data theft continuing even after patches shipped, and publicly acknowledged incomplete IOCs, so closing that detection gap has the highest immediate payoff for defenders tonight.
Get this report