< ciso
brief />
Tag Banner

All news with #jfrog tag

13 articles

Critical LMCache flaw allows remote code execution

๐Ÿ›ก๏ธ A critical vulnerability in LMCache lets unauthenticated attackers execute code on the cache server when it is configured to listen on a routable address. The flaw resides in multiprocess mode where ZeroMQ messages are unpickled before type checks, enabling crafted messages to run with the LMCache process's privileges. JFrog disclosed the issue (CVE-2026-105192) on October 7 and rated it 9.8/10; no patched release is available, and operators are advised to keep the server bound to localhost or restrict network access.
read more โ†’

CISA Adds Seven Actively Exploited Flaws to KEV

๐Ÿ›ก๏ธ The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added seven vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog after evidence of active exploitation. The list includes critical issues in SonicWall SMA, Sangoma Switchvox, JFrog Artifactory, Kludex Starlette, Kestra OSS, and Berri LiteLLM, ranging from SSRF and SQL injection to authentication bypasses and command injection. Several of the flaws have been observed in real-world attacks that deployed reverse shells, minted admin tokens, and delivered cryptocurrency miners. Federal agencies are being directed to prioritize patches under BOD 26-04 with staggered remediation deadlines in September 2026.
read more โ†’

Critical JFrog Artifactory Authentication Bypass Exploited

๐Ÿ›ก๏ธ A critical authentication bypass (CVE-2026-82329) in self-managed JFrog Artifactory is being actively exploited to mint admin tokens. The flaw exists in default configurations and allows unauthenticated attackers with network access to obtain administrative privileges. JFrog released fixes on August 28 for multiple Artifactory 7.x versions and says cloud instances were already protected.
read more โ†’

Critical JFrog Artifactory Bug Sparks Supply-Chain Alarm

๐Ÿ”’ A critical authentication bypass in JFrog Artifactory (CVE-2026-82329) is being actively exploited, allowing unauthenticated attackers under default configuration to obtain administrative privileges. Threat actors were observed creating admin tokens and enumerating users, groups and credentials, prompting urgent advisories to upgrade affected self-hosted versions and fortify cloud instances. Organizations are urged to patch exposed systems, revoke potentially compromised tokens, inspect logs and verify artifact integrity to mitigate downstream risks.
read more โ†’

JFrog Artifactory flaws risk supply chain metadata poisoning

๐Ÿ”’ Two vulnerabilities in JFrog Artifactory let anonymous or low-privileged users manipulate package metadata without altering artifacts, creating a potential software supply chain risk. Oligo Security reported the flaws to JFrog on June 25 and published research on August 20 detailing CVE-2026-69106 (score 8.8) and CVE-2026-65922 (score 5.4). The issues concern unverified X-Orig-Client-Uri header handling and writes into trusted .jfrog/ metadata paths. JFrog has issued fixes; operators are advised to upgrade, restrict anonymous access, and strip or overwrite hazardous headers at the routing boundary.
read more โ†’

148 npm Packages Masked as Student Proxies Abused

๐Ÿ” JFrog researchers found 148 npm packages posing as student web proxies that converted visitors' browsers into a DDoS botnet for roughly two weeks in May. The packages hosted a proxy UI but loaded a mutable remote script and a WebSocket flood generator, allowing attackers to run volumetric and control-plane attacks from unsuspecting users' tabs. Many packages have since been removed, but remnants and mutable loaders remain active, so network and build mitigations are advised.
read more โ†’

Critical FFmpeg MagicYUV Flaw Demands SBOM Focus

๐Ÿ”’ A critical heap out-of-bounds write in the MagicYUV decoder of FFmpeg (CVE-2026-8461), dubbed PixelSmash, can crash applications or enable remote code execution. Researchers at JFrog demonstrated full exploits against Jellyfin and Nextcloud by uploading crafted media files; any app using libavcodec is potentially affected. Users and vendors should upgrade to FFmpeg 8.1.2 or disable the MagicYUV decoder if unused.
read more โ†’

Target employees confirm leaked source code is authentic

๐Ÿ”’ Multiple current and former Target employees confirmed that source code and documentation shared by a threat actor match the company's internal systems. The leaked sample contains real system names (e.g., BigRED, TAP [Provisioning]), proprietary codenames and tooling references, including Vela-based CI/CD and JFrog Artifactory. Target enacted an "accelerated" change restricting access to its on-prem Git server to the corporate network and VPN after the disclosure.
read more โ†’

Target employees confirm leaked code after Git lockdown

๐Ÿ”’ Multiple current and former Target employees told BleepingComputer that a sample of source code and documentation published by a threat actor matches real internal systems. A screenshot of company-wide Slack shows an "accelerated" security change effective January 9, 2026, restricting access to git.target.com to Target-managed networks or VPN. The 14MB sample contains internal names like "BigRED" and "TAP" and references to Vela, Hadoop datasets, and JFrog Artifactory. The threat actor claims a full archive of ~860GB; the root cause remains under investigation.
read more โ†’

Critical Chaotic Deputy Bugs Risk Kubernetes Cluster Takeover

๐Ÿ”ด Researchers from JFrog disclosed critical command-injection vulnerabilities in Chaos-Mesh (tracked as CVE-2025-59358, CVE-2025-59360, CVE-2025-59361, and CVE-2025-59359) that allow an attacker with access to an unprivileged pod to execute shell commands via an exposed GraphQL API and the Chaos Daemon. Three of the flaws carry a CVSS score of 9.8 and can be exploited in default deployments, enabling denial-of-service or full cluster takeover. Users are advised to upgrade to Chaos-Mesh 2.7.3 or to disable the chaosctl tool and its port via the Helm chart as a workaround.
read more โ†’

Wesco Reimagines Risk Management with Data Consolidation

๐Ÿ” Wesco consolidated thousands of security alerts into a unified risk framework to separate urgent threats from noise. By integrating more than a dozen platforms โ€” including GitHub, Azure DevOps, Veracode, JFrog, Kubernetes, Microsoft Defender, and CrowdStrike โ€” the company applied ASPM, threat modeling, a security champions program, and AI-driven automation to prioritize remediation. The initiative reduced duplication, saved developer time, and improved risk visibility across the organization.
read more โ†’

Malicious npm Code Reached 10% of Cloud Environments

โš ๏ธ Security researchers warn a supplyโ€‘chain attack on npm briefly propagated trojanized versions of widely used packages after the developer account qix was hijacked via social engineering. The malicious updates contained cryptoโ€‘stealing payloads that could rewrite wallet recipients in browsers if bundled into frontend builds. Vendor Wiz reports the code was present in about 10% of cloud environments during a twoโ€‘hour window, and JFrog says additional accounts, including DuckDB, were impacted. Organizations are advised to blocklist affected versions, rebuild from clean caches, invalidate CDN assets, and hunt for affected bundles and anomalous signing activity.
read more โ†’

Supply-Chain Attacks on Nx and React Expose Dev Credentials

๐Ÿ”’ A coordinated supply-chain campaign compromised multiple npm packages โ€” most notably the Nx build system โ€” and used post-install scripts to harvest developer assets across enterprise environments. Wiz found the malware weaponized local AI CLI tools to exfiltrate filesystem contents, tokens, SSH keys, and environment variables. Separately, JFrog uncovered obfuscated malicious React packages designed to steal Chrome data. Vendors removed the packages and recommend rotating credentials, removing affected versions, and auditing developer and CI systems.
read more โ†’