Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (2 September 2026)
Published: Loading…
At a Glance
- JFrog Artifactory flaw CVE-2026-82329 was exploited days after disclosure, with attackers minting themselves administrator tokens.
- CrowdStrike and international law enforcement disrupted the 23-year-old Sality botnet, isolating over 15,000 infected machines worldwide.
- A 33-hour BGP hijack diverted Softaculous and Virtualizor traffic, delivering a malicious Virtualizor update package.
- Attackers stole a METR API key and consumed AI credits worth roughly $600,000 over three weeks.
- BREEZE COMET executed hundreds of fraudulent transactions against Brazilian financial systems including Pix and Boleto.
- Iranian group Nimbus Manticore delivered cross-platform NodeRabbit and PollCat RATs via fake coding tests.
Editorial Analysis
The gap between disclosure and exploitation continued to shrink today. JFrog's Artifactory flaw was patched on Friday and under active attack by Tuesday, while Langflow's RCE bug was also exploited within days of disclosure. PaperCut's already-patched zero-days are now being used for data theft. Unlike the PaperCut bypass reported on 29 August, these cases are not second-round fixes failing — the initial patches simply did not give defenders enough time before attackers began looking for vulnerable systems.
Financially motivated actors also showed a shift towards direct manipulation of payment infrastructure rather than opportunistic fraud. BREEZE COMET spent months embedded in Brazilian banks' core systems before executing hundreds of transactions within a 24–48 hour window, a level of patience and access more commonly associated with espionage than conventional cybercrime. Sality's low-effort, decades-old clipboard-hijacking model sits at the other end of the spectrum: one relies on persistent access to specific financial infrastructure, the other on scale and automation.
Highlights of the Day
METR Details Two Security Incidents Involving API Theft and Probing
METR disclosed two 2026 security incidents, including a March breach where attackers stole a public-model API key from an exposed personal EC2 instance and consumed roughly $600,000 in credits. In May, attackers conducted a sustained probing campaign while a separate bug in METR's public transcript viewer briefly exposed unpublished evaluation data. METR found no evidence that sensitive data was accessed in either incident.
Critical JFrog Artifactory Flaw Exploited Days After Disclosure
JFrog patched CVE-2026-82329, a critical authentication bypass in Artifactory allowing unauthenticated attackers to gain administrative privileges under default configuration. WatchTowr reported in-the-wild exploitation, observing attackers minting admin tokens and enumerating users, groups, and credential sets. Cloud instances have been patched, while self-hosted customers are advised to update to fixed versions.
CrowdStrike Leads Takedown of Two-Decade-Old Sality Botnet
CrowdStrike, alongside international law enforcement, disrupted the Sality peer-to-peer botnet on 31 August 2026, isolating over 15,000 infected machines worldwide. The operation used peer list manipulation to cut bots off from their command network, exploiting the P2P protocol's lack of authentication. The botnet's primary payload, EggJagger, had stolen an estimated $150,000 in cryptocurrency through clipboard-hijacking attacks.
BGP Hijack Diverts Softaculous Traffic for 33 Hours, Delivers Malware
A 33-hour BGP hijack diverted traffic from Softaculous and Virtualizor systems by announcing a more specific route than upstream provider Hetzner normally advertised. The attacker obtained a valid Let's Encrypt TLS certificate through the hijacked routing, avoiding certificate warnings, and delivered a malicious Virtualizor update package to a handful of installations. Softaculous is urging customers to reset credentials, rotate API keys, and check servers for a suspicious systemd unit.
Microsoft Tracks Fake Software Download Campaign Targeting China
Microsoft Defender Experts identified a malware campaign using counterfeit download sites to impersonate vendors including Razer, Kaspersky, and Microsoft Edge, primarily targeting Chinese-speaking users. Downloaded installer archives regenerate a new hash on every request while keeping the same filename, indicating server-side payload generation. The malware disables Windows Defender protections, deletes shadow copies, and establishes command-and-control over non-standard ports, with activity linked to the Silver Fox campaign.
Financially Motivated Group Targets Brazilian Banking Systems
Google Threat Intelligence Group is tracking BREEZE COMET, a financially motivated actor manipulating Brazilian payment systems including Pix and Boleto to conduct fraudulent transfers. The group compromises trusted government websites to stage malware, deploys custom backdoors written in Rust, Nim and Go, and uses generative AI to accelerate script development. Within 24 to 48 hours of gaining access to core financial applications, the actor executed waves of hundreds of fraudulent transactions.
Daily Coverage