Daily Security Intel

Archives
Log in
Subscribe
September 2, 2026

[SecurityIntel] 02 Sep | Critical Langflow and JFrog Flaws Exploited Wildly

SECURITYINTEL DAILY BRIEF

■ ThreatIntel Brief

Wednesday, September 02, 2026

INTEL CONFIDENCE  70%

THREAT LEVEL

CRITICAL

THREAT OF THE DAY

Critical Langflow and JFrog Flaws Exploited Wildly

CRITICAL

5

C2 IPs

0

OTX IOCs

36

ARTICLES

■ ANALYST TLDR

Active exploitation of critical vulnerabilities in Langflow (CVE-2026-0768) and JFrog Artifactory (CVE-2026-82329) is leading to immediate credential theft and administrative takeover. Additionally, sophisticated infrastructure attacks, including BGP hijacking of Virtualizor updates and Chinese state-sponsored targeting of Cisco routers, highlight a severe threat to trust layers and supply chains. Organizations must prioritize patching exposed assets and securing API keys against aggressive credential-harvesting campaigns.

■ CRITICAL STORIES

CRITICAL#1

Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure

Threat actors are actively exploiting CVE-2026-82329, a CVSS 9.8 authentication bypass vulnerability in JFrog Artifactory, allowing them to generate administrative tokens and compromise software supply chains.

CRITICAL#2

Hackers push malicious Virtualizor update in BGP hijacking attack

Attackers successfully hijacked BGP routing for Virtualizor's update infrastructure, redirecting legitimate VPS management servers to malicious servers that pushed compromised software updates.

CRITICAL#3

Critical Langflow flaw exploited to steal OpenAI and AWS keys

Attackers are actively exploiting CVE-2026-0768, an unauthenticated RCE flaw in the Langflow AI framework, to execute arbitrary Python code and harvest highly sensitive cloud and AI API credentials.

HIGH#4

China's 'Fire Ant' campaign used compromised Cisco routers as platform for more attacks

The Chinese state-sponsored group "Fire Ant" compromised Cisco routers to build a resilient operational platform, directly undermining the trust layer of the targeted network environments.

■ CVEs IDENTIFIED

CVE-2026-0768

Langflow — Unauthenticated Remote Code Execution / Arbitrary Python code execution

Critical

CVE-2026-82329

JFrog Artifactory — Authentication bypass to mint admin tokens

Critical

[CVE-TBD]

Microsoft Exchange Server — Authentication bypass allowing hijacking of user mailboxes

High

[CVE-TBD]

Ruby on Rails — Unspecified flaw exploited in credential-probing and C2 activity

Critical

■ THREAT ACTORS

Fire Ant

State-sponsored (China)

Compromising Cisco routers as a platform for further attacks

Breeze Comet (UNC5669)

Financially motivated

Targeting Brazilian financial, retail, and e-commerce organizations with fraudulent transactions

Nimbus Manticore

State-sponsored (Iran)

Posing as recruiters to deliver cross-platform RATs via coding tests to Linux and macOS systems

■ ATT&CK TTPs

T1190
Exploit Public-Facing Application | Exploiting CVE-2026-0768 (Langflow) and CVE-2026-82329 (JFrog Artifactory)
T1584.004
Compromise Infrastructure: Server Software Common Utilities | Abuse of Faronics Deploy admin tool to install ScreenConnect
T1204.002
User Execution: Malicious File | Counterfeit installers, fake GTA 6 copy, and coding tests delivering RATs
T1539
Steal Web Session Cookie | Infostealers hijacking Claude accounts via session cookies
T1556
Modify Authentication Process | Authentication bypass on JFrog Artifactory (CVE-2026-82329) and Microsoft Exchange
T1036
Masquerading | Counterfeit installers and ClickFix/TerminalFix fake CAPTCHAs

■ PATCH PRIORITY

[P1 PATCH NOW]≤24h

Langflow — CVE-2026-0768 allows unauthenticated remote code execution (RCE) and is actively exploited in the wild — SecurityWeek

[P1 PATCH NOW]≤24h

JFrog Artifactory — CVE-2026-82329 allows authentication bypass and admin token minting, with active exploitation reported — The Hacker News

[P1 PATCH NOW]≤24h

Microsoft Exchange Server — High-severity authentication bypass vulnerability allows hijacking of all user mailboxes — BleepingComputer

[P2 PATCH NOW]≤72h

Ruby on Rails — Flaw exploited in credential-probing and C2 activity — The Hacker News

■ RECOMMENDED ACTIONS TODAY

1[P1] Patch Langflow immediately to address CVE-2026-0768 and prevent unauthenticated remote code execution and API key theft.
2[P1] Patch JFrog Artifactory immediately to remediate CVE-2026-82329 to block authentication bypass and administrative token generation.
3[P1] Apply security updates to all internet-exposed Microsoft Exchange servers to mitigate the high-severity authentication bypass vulnerability.
4[P2] Audit Faronics Deploy and ScreenConnect configurations to prevent unauthorized administrative access and software deployments.
5[P2] Implement strict BGP route filtering and monitoring to protect against BGP hijacking attacks targeting software update infrastructure like Virtualizor.
LIVE IOC FEED

C2 IP BLOCKLIST  ·  AbuseCH Feodo  ·  Showing 5 of 5

IP ADDRESS

162.243.103.246

PORT

8080

STATUS

OFFLINE

MALWARE

Emotet

COUNTRY

US

IP ADDRESS

50.16.16.211

PORT

443

STATUS

ONLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

34.204.119.63

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

178.62.3.223

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

GB

IP ADDRESS

27.133.154.218

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

JP

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs
Updated daily · Export as CSV to import directly into your tools

■  Open Full IOC Sheet  →

IOC SOURCES: AbuseCH Feodo  ·  AlienVault OTX
NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

Don't miss what's next. Subscribe to Daily Security Intel:
← Newer [SecurityIntel] 03 Sep | BGP Hijack Delivers Malicious Virtualizor Software Updates Older → [SecurityIntel] 01 Sep | Chinese Fire Ant Hackers Hijack Cisco Routers
Powered by Buttondown, the easiest way to start and grow your newsletter.