SECURITYINTEL DAILY BRIEF ■ ThreatIntel BriefWednesday, September 02, 2026 INTEL CONFIDENCE 70% | THREAT LEVEL CRITICAL |
|
THREAT OF THE DAY Critical Langflow and JFrog Flaws Exploited Wildly | CRITICAL |
|
5 C2 IPs | 0 OTX IOCs | 36 ARTICLES |
|
■ ANALYST TLDR Active exploitation of critical vulnerabilities in Langflow (CVE-2026-0768) and JFrog Artifactory (CVE-2026-82329) is leading to immediate credential theft and administrative takeover. Additionally, sophisticated infrastructure attacks, including BGP hijacking of Virtualizor updates and Chinese state-sponsored targeting of Cisco routers, highlight a severe threat to trust layers and supply chains. Organizations must prioritize patching exposed assets and securing API keys against aggressive credential-harvesting campaigns. |
|
■ CRITICAL STORIES Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure Threat actors are actively exploiting CVE-2026-82329, a CVSS 9.8 authentication bypass vulnerability in JFrog Artifactory, allowing them to generate administrative tokens and compromise software supply chains. |
Hackers push malicious Virtualizor update in BGP hijacking attack Attackers successfully hijacked BGP routing for Virtualizor's update infrastructure, redirecting legitimate VPS management servers to malicious servers that pushed compromised software updates. |
Critical Langflow flaw exploited to steal OpenAI and AWS keys Attackers are actively exploiting CVE-2026-0768, an unauthenticated RCE flaw in the Langflow AI framework, to execute arbitrary Python code and harvest highly sensitive cloud and AI API credentials. |
China's 'Fire Ant' campaign used compromised Cisco routers as platform for more attacks The Chinese state-sponsored group "Fire Ant" compromised Cisco routers to build a resilient operational platform, directly undermining the trust layer of the targeted network environments. |
|
■ CVEs IDENTIFIED CVE-2026-0768 Langflow — Unauthenticated Remote Code Execution / Arbitrary Python code execution |
CVE-2026-82329 JFrog Artifactory — Authentication bypass to mint admin tokens |
[CVE-TBD] Microsoft Exchange Server — Authentication bypass allowing hijacking of user mailboxes |
[CVE-TBD] Ruby on Rails — Unspecified flaw exploited in credential-probing and C2 activity |
|
■ THREAT ACTORS Fire Ant | State-sponsored (China) |
Compromising Cisco routers as a platform for further attacks |
Breeze Comet (UNC5669) | Financially motivated |
Targeting Brazilian financial, retail, and e-commerce organizations with fraudulent transactions |
Nimbus Manticore | State-sponsored (Iran) |
Posing as recruiters to deliver cross-platform RATs via coding tests to Linux and macOS systems |
|
|
|
■ ATT&CK TTPs | T1190 | | Exploit Public-Facing Application | Exploiting CVE-2026-0768 (Langflow) and CVE-2026-82329 (JFrog Artifactory) |
| T1584.004 | | Compromise Infrastructure: Server Software Common Utilities | Abuse of Faronics Deploy admin tool to install ScreenConnect |
| T1204.002 | | User Execution: Malicious File | Counterfeit installers, fake GTA 6 copy, and coding tests delivering RATs |
| T1539 | | Steal Web Session Cookie | Infostealers hijacking Claude accounts via session cookies |
| T1556 | | Modify Authentication Process | Authentication bypass on JFrog Artifactory (CVE-2026-82329) and Microsoft Exchange |
| T1036 | | Masquerading | Counterfeit installers and ClickFix/TerminalFix fake CAPTCHAs |
|
■ PATCH PRIORITY Langflow — CVE-2026-0768 allows unauthenticated remote code execution (RCE) and is actively exploited in the wild — SecurityWeek |
JFrog Artifactory — CVE-2026-82329 allows authentication bypass and admin token minting, with active exploitation reported — The Hacker News |
Microsoft Exchange Server — High-severity authentication bypass vulnerability allows hijacking of all user mailboxes — BleepingComputer |
Ruby on Rails — Flaw exploited in credential-probing and C2 activity — The Hacker News |
|
|
|
■ RECOMMENDED ACTIONS TODAY | 1 | [P1] Patch Langflow immediately to address CVE-2026-0768 and prevent unauthenticated remote code execution and API key theft. |
| 2 | [P1] Patch JFrog Artifactory immediately to remediate CVE-2026-82329 to block authentication bypass and administrative token generation. |
| 3 | [P1] Apply security updates to all internet-exposed Microsoft Exchange servers to mitigate the high-severity authentication bypass vulnerability. |
| 4 | [P2] Audit Faronics Deploy and ScreenConnect configurations to prevent unauthorized administrative access and software deployments. |
| 5 | [P2] Implement strict BGP route filtering and monitoring to protect against BGP hijacking attacks targeting software update infrastructure like Virtualizor. |
|
|
|
C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5 IP ADDRESS 162.243.103.246 | PORT 8080 | STATUS OFFLINE | MALWARE Emotet | COUNTRY US |
IP ADDRESS 50.16.16.211 | PORT 443 | STATUS ONLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 34.204.119.63 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 178.62.3.223 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY GB |
IP ADDRESS 27.133.154.218 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY JP |
|
FULL IOC EXPORT — GOOGLE SHEET All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools ■ Open Full IOC Sheet → |
|
IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB |