Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Y Combinator’s Garry Tan wants US open-weight AI labs to ‘distill’ frontier models, too

    September 12, 2026

    Artifactory flaws chained in attacks deploying backdoor malware

    September 12, 2026

    Blockstream bets 600 Bitcoin by rejecting Liquid hacker’s $50 million bounty demand

    September 12, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Y Combinator’s Garry Tan wants US open-weight AI labs to ‘distill’ frontier models, too
    • Artifactory flaws chained in attacks deploying backdoor malware
    • Blockstream bets 600 Bitcoin by rejecting Liquid hacker’s $50 million bounty demand
    • Israel’s Hard Power Is Its Soft Power
    • Thousands of ebikes seized by London councils as anger rises over blocked paths | Cycle hire schemes
    • From black-clad agitators to an appeal for ‘Tommo’s Mum’: an unsettling week with the Patriot Platform | Immigration and asylum
    • We Tried the Most Popular Mushroom Coffees. These Are the Best (2026)
    • Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, September 12
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Artifactory flaws chained in attacks deploying backdoor malware

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 12, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Threat actors are exploiting critical and high-severity vulnerabilities in JFrog Artifactory to bypass authentication, gain administrative privileges, and deploy a Rust backdoor on vulnerable self-hosted servers.

    A new report from cloud security company Wiz confirmed exploitation across multiple environments, including an exploit chain that combines CVE-2026-42018 and CVE-2026-42016.

    The third vulnerability is CVE-2026-82329, a critical authentication bypass that offensive security company watchTowr observed being exploited earlier this month to mint administrator tokens.

    According to Wiz, attackers exploit CVE-2026-42018 to obtain a JSON Web Token (JWT) belonging to an internal Artifactory anonymous user, even when anonymous access is disabled, with low privileges.

    Then they increase permissions to admin level by exploiting CVE-2026-42016, caused by insufficient token validation.

    Between August 15 and September 8, multiple threat actors exploited the two vulnerabilities to obtain a JWT for the internal anonymous user and then exchange it for an admin-scoped token.

    The researchers note that in some cases the attacker took less than five minutes to create an administrator account.

    After creating admin accounts and generating long-lived access tokens, the attackers installed malicious Groovy plugins to execute arbitrary commands and established persistence by deploying a Rust-based backdoor.

    “Between August 15 and September 8, 2026, we observed multiple actors chain CVE-2026-42018 and CVE-2026-42016 against self-hosted Artifactory instances,” Wiz says.

    “Across multiple cases, we observed a custom Rust backdoor with C2 capabilities being dropped.”

    In the next stage, the threat actor downloaded additional payloads into /dev/shm, /tmp, and /var/tmp, uploaded webshells, stole Artifactory configuration data and cluster join keys, enumerated repositories, tokens, and users, and added their SSH keys to newly created accounts.

    Wiz warns that between 49% and 62% of reachable Artifactory instances are vulnerable to at least one of the three flaws.

    System administrators are recommended to upgrade immediately to one of the following Artifactory release versions or later:

    • 7.111.21
    • 7.117.28
    • 7.125.20
    • 7.133.29
    • 7.146.38
    • 7.161.20

    After upgrading, investigate internet-exposed instances for unexpected token creation, rogue administrator accounts, suspicious plugin activity, and enumeration requests, and restrict access to trusted systems only.

    Wiz has listed indicators of compromise (IoCs) associated with the observed attacks to help defenders detect them quickly.

    BleepingComputer has contacted JFrog to confirm the reported activity, but we have not received a response as of publication.


    article image

    Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

    Save your seat

    Artifactory attacks Backdoor Chained deploying flaws Malware
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware

    Passkey-themed phishing attacks lead to Microsoft 365 data theft

    PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws

    Your Critical Vulnerabilities Might Not Be Your Biggest Risk

    Users in Houthi-Held Yemen Tried to Develop Advanced Weapons With AI, Anthropic Says

    GitLab Vulnerability Exploited One Day After Disclosure

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Y Combinator’s Garry Tan wants US open-weight AI labs to ‘distill’ frontier models, too

    September 12, 2026

    Artifactory flaws chained in attacks deploying backdoor malware

    September 12, 2026

    Blockstream bets 600 Bitcoin by rejecting Liquid hacker’s $50 million bounty demand

    September 12, 2026

    Israel’s Hard Power Is Its Soft Power

    September 12, 2026
    Latest Posts

    After 3 reverse stock splits and a $13.5M loss, this real estate firm bet $8M on crypto it may not be allowed to withdraw

    August 3, 2026

    There Are 2 Eclipses This August. Here’s How to See Them

    August 3, 2026

    Europe’s ETS revision is an opportunity to strengthen maritime competitiveness – POLITICO

    August 3, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Y Combinator’s Garry Tan wants US open-weight AI labs to ‘distill’ frontier models, too

    September 12, 2026

    Artifactory flaws chained in attacks deploying backdoor malware

    September 12, 2026

    Blockstream bets 600 Bitcoin by rejecting Liquid hacker’s $50 million bounty demand

    September 12, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.