Cybersecurity Brief — 2026-09-01
Active Exploitation & Critical Vulnerabilities
- JFrog Artifactory CVE-2026-82329 (CVSS 9.8) under active exploitation — Threat actors are exploiting a critical authentication-bypass flaw in JFrog Artifactory mere days after the August 28 patch. The vulnerability allows unauthenticated attackers to mint administrator tokens and enumerate users, groups, credential sets, and federated access topologies. Affected versions span 7.111.4 through 7.161.19. watchTowr reports exploitation from multiple IPs across geographies; broad scanning has not yet been observed but is expected. Organizations must patch internet-exposed instances immediately, inspect audit logs, rotate credentials, and investigate connected systems for backdoors. (Source: The Hacker News, The Register)
Threat Actor Activity
-
Breeze Comet (UNC5669) targeting Brazilian financial sector — Google Threat Intelligence Group and Mandiant profile this financially motivated e-crime group (active since September 2023) specializing in manipulating Brazilian payment systems (Pix, STR, Boleto) to execute fraudulent transfers. Initial access via password spraying, voice phishing (vishing) impersonating IT support to install RMM tools (AnyDesk), and exploitation of vulnerable JBoss AS servers. The group uses a custom malware suite including COBALTSPIN (Rust-based SOCKS5-over-WebSocket tunneler for lateral movement through firewalls), XWorm, Chisel, Impacket, ADRecon, and a custom LDAP brute-forcer (REALBREEZE). Infrastructure shows signs of expansion toward Latin America and Africa. (Source: The Hacker News)
-
The Gentlemen ransomware crew hits Nutex — The ransomware group claims sensitive data theft from Nutex, a healthcare operator, and threatens publication while the company assesses which records escaped. (Source: The Register)
Data Breaches & Identity Theft
-
FBI investigating dark web service selling 153M+ driver's licenses — A new service dubbed "Nexus" on the Russian-language Exploit forum offers digital scans of >153M U.S./Canadian driver's licenses, >10M ID cards, >3M travel documents, and 579K medical cards. Records include IR/UV scans with timestamps correlating to car rental transactions (Hertz), suggesting a breach at a major identity verification company used by Fortune 500 firms. The FBI New Orleans field office has opened an inquiry. Fresh records are being added at ~400K/day. (Source: Krebs on Security)
-
McKesson breach; ShinyHunters demands $55.2M — Healthcare giant McKesson confirms a breach affecting millions of patient records; extortion actor ShinyHunters claims access to pacemaker data and is demanding $55.2M. (Source: The Register)
Infrastructure & Network Attacks
- 33-hour BGP hijack of Softaculous traffic — A BGP hijack redirected traffic for hosting software vendor Softaculous for 33 hours. The company advises customers to reset all credentials and hunt for malicious packages that may have been served during the hijack window. (Source: The Register)
Malware & Attack Techniques
- ClickFix evolution: PNG-staged malware with custom reverse tunnels — A new ClickFix campaign hides malicious payloads in PNG images and deploys a custom reverse tunnel on victim machines, enabling multi-stage attack chains that evade traditional detection. (Source: The Register)
Industry & Law Enforcement
-
Two alleged TeamPCP hackers arrested in Australia — Australian authorities arrested two men believed to be members of the TeamPCP cybercrime group. (Source: Krebs on Security)
-
Palo Alto Networks acquires AI Agent Platform Console — The acquisition was announced alongside Q4 results showing 34% revenue growth and strong next-gen security ARR growth, signaling continued consolidation around AI-driven security operations. (Source: SecurityWeek)