← Back to live feed1 story
The Cybersecurity and Infrastructure Security Agency designated a group of seven newly weaponized software flaws as urgent security risks on September 3. These vulnerabilities allow threat actors to deploy reverse shells and cryptocurrency miners across networks utilizing LiteLLM and Switchvox while harvesting API keys.
The JFrog Artifactory vulnerability features an authentication bypass in default configurations that grants unauthenticated users with network access administrative privileges through the minting of administrator tokens. Because the tool manages container images and AI model artifacts, a successful breach potentially allows attackers to manipulate the software supply chain before code reaches production.
Sign in to suggest edits
Key sources
- SOURCE@thehackersnews“deploy crypto miners and reverse shells, mint admin tokens, and harvest API keys”x.com