Chisato · · 6 min read JFrog Artifactory CVE-2026-82329: Critical Auth Bypass
Attackers are exploiting CVE-2026-82329, a CVSS 9.8 auth bypass in self-hosted JFrog Artifactory, to mint admin tokens. Affected versions, fixes, mitigations.
Topic
5 posts tagged “Supply Chain”.
Chisato · · 6 min read Attackers are exploiting CVE-2026-82329, a CVSS 9.8 auth bypass in self-hosted JFrog Artifactory, to mint admin tokens. Affected versions, fixes, mitigations.
Chisato · · 5 min read A compromised account poisoned Rust crates arrayref, internment, and append-only-vec with a build-time payload. The attack, the mechanism, and how to respond.
Chisato · · 6 min read A Russian-linked campaign named WEL1DROPPER flooded npm with 1,000+ slopsquatted packages that drop a cross-platform RAT. How the attack works and how to defend.
Chisato · · 5 min read EY disclosed a breach after attackers accessed a third-party IT support platform and downloaded client tax documents. What happened, what leaked, and what to do.
Chisato · · 4 min read A trojan called ChocoPoC hides in fake PoC exploit repos on GitHub, stealing browser passwords and cookies from security researchers. How the attack works.