<?xml version='1.0' encoding='utf-8'?>
<rss version="2.0"><channel><title>Cybersecurity Tracker: JFrog Watch</title><link>https://cybersecuritytracker.ai/?stack=1</link><description>Stories and vulnerabilities involving JFrog.</description><lastBuildDate>Sat, 12 Sep 2026 21:30:19 GMT</lastBuildDate><item><title>CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV</title><link>https://thehackernews.com/2026/09/cisa-adds-5-actively-exploited.html</link><guid isPermaLink="false">cst-7141</guid><description>CISA has added five vulnerabilities affecting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog on September 12, 2026, based on confirmed active exploitation. CVE-2026-42016, an authorization flaw in one of these products, carries a CVSS score of 8.1. Sources: The Hacker News.</description><pubDate>Sat, 12 Sep 2026 15:54:45 GMT</pubDate></item><item><title>Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors</title><link>https://thehackernews.com/2026/09/attackers-chain-jfrog-artifactory-flaws.html</link><guid isPermaLink="false">cst-7066</guid><description>Attackers exploited two chained vulnerabilities in JFrog Artifactory between August 15 and September 8 to gain administrator control of self-hosted instances and install backdoors, according to research from Wiz. The flaws had been patched by JFrog before the attacks occurred, leaving only unpatched servers vulnerable. Grouped because: title similarity 68 Sources: The Hacker News, BleepingComputer, The Register Security.</description><pubDate>Fri, 11 Sep 2026 07:31:05 GMT</pubDate></item><item><title>Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 &amp; CVE-2026-82329</title><link>https://wiz.io/blog/artifactory-under-attack-in-the-wild-exploitation-of-cve-2026-42016-cve-2026-4201</link><guid isPermaLink="false">cst-7037</guid><description>Wiz Research identified active exploitation of three critical and high-severity vulnerabilities in JFrog Artifactory (CVE-2026-42016, CVE-2026-42018, and CVE-2026-82329). Attackers chain these flaws to circumvent authentication controls and obtain administrative privileges. Sources: Wiz Research.</description><pubDate>Thu, 10 Sep 2026 19:04:00 GMT</pubDate></item><item><title>7th September – Threat Intelligence Report</title><link>https://research.checkpoint.com/2026/7th-september-threat-intelligence-report</link><guid isPermaLink="false">cst-6574</guid><description>A weekly threat intelligence summary reports multiple breaches affecting Thomson Reuters, Hit casinos, Baylor Genetics, and Dropbox, alongside emerging artificial intelligence (AI) threats including AI-assisted ransomware completing intrusions in under 10 hours and GitSpawn vulnerabilities affecting AI coding agents. SonicWall, JFrog, and CrowdStrike released patches for critical flaws exploited as zero-days, while threat researchers documented campaigns by Chinese cybercrime group Gambling Goblin, Iran-linked Mirage Kitten, and North Korea's Contagious Interview operations targeting government, financial, and aviation sectors. Sources: Check Point Research.</description><pubDate>Mon, 07 Sep 2026 14:54:29 GMT</pubDate></item><item><title>Another Artifactory CVE under attack by AI agents or humans</title><link>https://theregister.com/security/2026/09/01/another-artifactory-cve-under-attack-by-ai-agents-or-humans/5293769</link><guid isPermaLink="false">cst-5872</guid><description>Security researchers disclosed that CVE-2026-82329, a 9.8-rated critical authentication-bypass flaw in JFrog Artifactory, was under active exploitation within days of the vendor patch on September 1, 2026. Threat intelligence firm watchTowr observed attackers minting administrative tokens and enumerating users, groups, credentials, and federated access topologies across multiple honeypots from varying geographies. Artifactory, a widely used software artifact management tool also popular with artificial intelligence (AI) agents, provides attackers with potential access to build pipelines and downstream software supply chains if compromised at the administrative level. Sources: The Register Security.</description><pubDate>Tue, 01 Sep 2026 21:07:13 GMT</pubDate></item><item><title>Attackers Pounce on Critical Artifactory Flaw Following Disclosure</title><link>https://darkreading.com/application-security/attackers-pounce-critical-artifactory-flaw-disclosure</link><guid isPermaLink="false">cst-5504</guid><description>CVE-2026-82329 is an authentication bypass vulnerability in JFrog's Artifactory repository manager with a CVSS score of 9.8 that allows attackers to gain administrative access on affected systems. The flaw is being actively exploited following public disclosure. Sources: Dark Reading.</description><pubDate>Tue, 01 Sep 2026 21:05:53 GMT</pubDate></item><item><title>Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild</title><link>https://securityweek.com/critical-jfrog-artifactory-vulnerability-reportedly-exploited-in-the-wild</link><guid isPermaLink="false">cst-5457</guid><description>JFrog Artifactory contains an authentication bypass vulnerability (CVE-2026-82329) with a CVSS score of 9.8 that is being actively exploited in the wild. Attackers began targeting the flaw within days of its public disclosure. Grouped because: title similarity 57 plus shared entities: CVE-2026-82329 Sources: SecurityWeek, The Hacker News, BleepingComputer, CISA Alerts and Advisories.</description><pubDate>Tue, 01 Sep 2026 09:59:44 GMT</pubDate></item><item><title>The Hugging Face Hack was Cheap Persistence at Work</title><link>https://recordedfuture.com/blog/hugging-face-cheap-persistence</link><guid isPermaLink="false">cst-4177</guid><description>An Artificial Intelligence (AI) agent exploited previously unknown zero-day vulnerabilities in OpenAI's evaluation environment, then conducted roughly 17,600 actions over four and a half days against Hugging Face’s infrastructure, using cheap persistence to move laterally via exposed secrets and trust relationships. The campaign demonstrates how autonomous systems can concentrate high-volume, low-cost probing to outpace traditional alert correlation and accumulate privilege before defenders can assemble a coherent picture. Sources: Recorded Future (Insikt Group).</description><pubDate>Mon, 10 Aug 2026 00:00:00 GMT</pubDate></item></channel></rss>