contact@trustinfinitech.com (573) 234-6540

Weekly Security Roundup for September 4, 2026

Hackers Exploit Critical JFrog Artifactory Flaw to Forge Admin Tokens

A critical authentication bypass vulnerability is being actively exploited in self-managed instances of JFrog Artifactory. Because the vulnerability exists in default configurations, unauthenticated remote attackers are successfully exploiting it to mint their own administrative tokens.

With admin access, threat actors can enumerate users, alter security configurations, and critically, poison existing software packages. Because Artifactory is a trusted repository for enterprise software builds, compromised artifacts could be automatically pulled by downstream continuous integration and continuous deployment systems, leading to widespread supply chain infections.

The vulnerability is direct and devastating: unauthenticated remote access leading to complete administrative control of your artifact repository. For any organization using Artifactory, this means attackers could inject malicious code into legitimate packages that your build systems automatically pull and deploy.

This is supply chain attack at the infrastructure level. Your build pipeline becomes the weapon.

Read more: https://www.bleepingcomputer.com/news/security/hackers-exploit-critical-jfrog-artifactory-flaw-to-forge-admin-tokens/


Critical Langflow Vulnerability Exploited as Attacks on AI Platform Rise

A severe remote code execution vulnerability in Langflow, a popular low-code platform for designing AI agents, is currently under heavy exploitation. Security firm VulnCheck reported widespread attacks against its honeypots from global IP addresses, observing threat actors conducting reconnaissance, harvesting credentials and API keys, and exfiltrating Langflow source code.

Some attackers are actively hunting for previously backdoored Langflow installations to establish their own persistence. This underscores the growing attacker interest in internet-exposed AI development environments, which often house highly sensitive secrets and access to powerful compute resources.

Internet-exposed AI development environments are high-value targets. They contain API keys, credentials, and access to compute resources. Compromised Langflow instances give attackers both initial access and the tools to build more sophisticated attacks.

Read more: https://www.darkreading.com/vulnerabilities-threats/critical-langflow-flaw-exploited-attacks-rise


Microsoft Warns of TerminalFix Attacks Deploying Reverse Tunnels

A new variant of the “ClickFix” social engineering tactic, dubbed “TerminalFix,” is utilizing fake Cloudflare CAPTCHA prompts to trick users into pasting malicious PowerShell commands into the Windows Terminal. Instead of merely dropping an infostealer, this highly sophisticated attack chain downloads a ZIP file, loads a malicious DLL into memory, and extracts secondary payloads hidden via steganography inside the pixel data of PNG images.

The ultimate payload establishes a custom Python reverse tunnel over an encrypted WebSocket, granting the attacker a persistent foothold to perform internal Active Directory reconnaissance and pivot deeper into the victim’s corporate network.

The sophistication is notable: fake CAPTCHA prompts, DLL injection, steganographic payload hiding, encrypted tunnels. This isn’t basic social engineering. This is a complete attack chain designed to bypass detection at every layer. A single user click, and attackers have persistent access inside your network.

Read more: https://www.bleepingcomputer.com/news/security/microsoft-warns-of-terminalfix-attacks-deploying-reverse-tunnels/


Data at Law Firms Quinn Emanuel, McDermott Exposed in Cyber Breaches

Prominent US law firms Quinn Emanuel and McDermott Will & Emery both recently disclosed data breaches stemming from targeted social engineering attacks. At Quinn Emanuel, attackers successfully bypassed security controls to access specific case files, including sensitive documents related to the short-selling firm Muddy Waters. Separately, McDermott reported a social engineering incident that exposed highly sensitive client data, including Social Security numbers and health information.

These incidents highlight how highly privileged professional services firms remain prime targets for sophisticated threat actors seeking confidential business and personal data.

Law firms are treasure troves of sensitive information: M&A data, litigation strategy, client financial information, intellectual property. When attackers target them through social engineering, the leverage is enormous. These weren’t technical breaches. They were social engineering attacks against privileged targets.

Read more: https://www.reuters.com/legal/government/data-law-firms-quinn-emanuel-mcdermott-exposed-cyber-breaches-2026-09-03/


Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root

A critical vulnerability has been identified in Cisco Nexus 9000 series switches that could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges. Network infrastructure devices like the Nexus 9000 are foundational to enterprise data centers, making high-severity flaws that grant root-level access incredibly dangerous.

Organizations utilizing these switches are urged to immediately apply the necessary patches or mitigations to prevent complete compromise of their core routing and switching environments.

Your network core is under attack. Unauthenticated remote access leading to root-level code execution on your switches means attackers can control traffic routing, intercept data, or disable network access entirely. This isn’t a peripheral device. This is your infrastructure foundation.

Read more: https://thehackernews.com/2026/09/critical-cisco-nexus-9000-flaw-lets.html


PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions

A new zero-day vulnerability in PaperCut’s widely used print management software is currently being exploited in the wild. The flaw affects all versions of PaperCut NG and MF editions, exposing a massive attack surface given the software’s ubiquitous deployment across enterprise, government, and education sectors.

Due to the active exploitation and the historical tendency for ransomware groups to weaponize print server vulnerabilities for initial access and lateral movement, administrators must prioritize isolating these servers and applying the vendor’s emergency updates immediately.

Print servers are often overlooked in security planning. They’re treated as peripheral. But they’re connected to everything: workstations, file servers, domain controllers. A compromised print server is a bridge into your entire network. This zero-day affects all versions, meaning patching must happen urgently.

Read more: https://thehackernews.com/2026/08/papercut-zero-day-exploited-in-attacks.html

← Back to News