TL;DR
JFrog Artifactory and Langflow critical flaws now actively exploited in the wild within days of disclosure. Attackers minting admin tokens and stealing API keys. Two Australian nationals arrested in connection with TeamPCP supply-chain attack campaign.
Executive Summary
- JFrog Artifactory (CVE-2026-82329, CVSS 9.8) authentication bypass exploited within days to mint administrative tokens; two sources confirm active attacks.
- Langflow open-source AI platform (CVE-2026-0768) RCE exploited to harvest OpenAI and AWS credentials; three sources document active in-the-wild campaigns.
- Malicious Packagist PHP packages injected into Vietnamese streaming sites to deliver iOS spyware targeting unpatched devices and cryptocurrency wallet seeds.
- Iranian Nimbus Manticore group employing cross-platform RATs via fake recruiter phishing, expanding Linux and macOS attack surface.
- Two alleged TeamPCP members arrested by Australian Federal Police; group linked to prolonged supply-chain attack spree.
Top Threats Today
1. JFrog Artifactory Authentication Bypass Under Active Attack
Severity: HIGH Affected: Technology
Threat actors are exploiting CVE-2026-82329, a critical authentication bypass in JFrog Artifactory, to mint administrative tokens mere days after public disclosure ⚠ [1][2]. The vulnerability carries a CVSS score of 9.8 and allows unauthenticated attackers to gain admin-level access on affected repository manager systems ⚠[1][2].
Sources:[1] The Hacker News[2] The Hacker News
Recommended Action
- Apply the latest JFrog Artifactory security patch immediately
- Audit administrative token creation logs for unauthorized entries
- Rotate API keys and credentials for any systems connected to Artifactory
- Segment Artifactory instances from the broader network pending patch validation
2. Langflow Critical RCE Exploited for Credential Harvesting
Severity: HIGH Affected: Technology
CVE-2026-0768, an unauthenticated remote code execution flaw in Langflow (an open-source AI application framework), is being actively exploited to steal OpenAI API keys, AWS credentials, and other sensitive tokens [1][2]. Threat actors are executing arbitrary Python code on vulnerable systems to exfiltrate authentication material [1][3].
Sources:[1] BleepingComputer[2] Dark Reading[3] SecurityWeek
Recommended Action
- Update Langflow to the latest patched version immediately
- Rotate all OpenAI and AWS API keys that may have been exposed
- Enable MFA on linked cloud service accounts
- Monitor CloudTrail/audit logs for unauthorized API activity
- Isolate vulnerable Langflow deployments from production environments until patched
3. Malicious PHP Packages Targeting iOS Wallet Theft
Severity: HIGH Affected: Technology
Security researchers identified 13 malicious Composer theme packages on Packagist that inject JavaScript into Vietnamese movie and comic streaming websites to deliver spyware targeting unpatched iOS devices, with a focus on stealing cryptocurrency wallet seeds [1]. The attack chain leverages compromised or typosquatted PHP libraries to reach mobile users.
Sources:[1] The Hacker News
Recommended Action
- Audit Composer dependencies for any packages from the identified malicious set
- Remove and replace compromised packages; notify users to update dependencies
- Implement Composer lock file verification and integrity checks in CI/CD pipelines
- Advise end users to install the latest iOS patches and enable two-factor authentication on cryptocurrency wallets
4. Iranian Nimbus Manticore Deploys Cross-Platform RATs via Recruiter Phishing
Severity: HIGH Affected: Technology
The Iranian Nimbus Manticore hacking group has been attributed to two previously undocumented malware families designed to infect Linux and Apple macOS systems via cross-platform remote access trojans, delivered through fake job recruiter phishing campaigns targeting developers [1]. The campaign expands the group's historical targeting footprint beyond Windows.
Sources:[1] The Hacker News
Recommended Action
- Alert development teams to verify recruiter identities through official company channels before engaging
- Implement email security controls to flag unsolicited coding tests and suspicious file attachments
- Deploy endpoint detection and response (EDR) agents on developer workstations and servers
- Monitor for execution of suspicious cross-platform RAT indicators across macOS and Linux systems
5. TeamPCP Supply-Chain Attackers Arrested in Australia
Severity: HIGH Affected: Technology
Australian Federal Police arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group responsible for conducting the longest running spree of software supply-chain attacks [1]. The group has perpetrated multiple supply-chain compromise campaigns over an extended period.
Sources:[1] Krebs on Security
Recommended Action
- Review threat intelligence feeds for TeamPCP indicators of compromise (IOCs) and malicious packages
- Audit software repositories and package managers for any compromised dependencies introduced by the group
- Strengthen software bill of materials (SBOM) practices and dependency verification
- Monitor for any newly attributed TeamPCP variants or successor operations
Additional Threats
Healthcare Breaches: BleepingComputer reports Aesto Health disclosed a breach affecting over 9.5 million patients [7], and Novocure confirmed a mid-August cyberattack exposing employee and patient data for more than 1,400 cancer patients [10].
Driver License Theft Service: Krebs on Security reports the FBI is investigating a dark web identity theft service launched this week selling digital scans of more than 153 million drivers licenses from the United States and Canada [11].
Faronics Deploy Abuse: BleepingComputer reports phishing actors are abusing the legitimate Faronics Deploy endpoint-management platform to install ScreenConnect remote support software and gain administrative access [6].
BGP Hijacking & Malicious Updates: BleepingComputer reports hackers hijacked BGP routing for Virtualizor VPS management software update infrastructure, redirecting update requests to malicious servers and delivering compromised updates [9].
Philippines Nuclear Agency Intrusion: Dark Reading reports threat actors exploited unpatched ownCloud vulnerabilities to breach the Philippines nuclear agency, stealing reactor databases, personnel records, and credential stores [16].
Iran’s NodeRabbit Malware: The Record reports Iranian cyber spies targeted aviation and fintech developers with NodeRabbit, a malware variant first discovered on a system in Afghanistan and later identified in Egypt and Ethiopia [23].
Breeze Comet Financial Fraud: The Hacker News reports the financially motivated threat actor Breeze Comet (formerly UNC5669) has executed hundreds of fraudulent transactions via Brazilian payment systems since 2024, targeting financial services, retail, and e-commerce organizations [2].
Fire Ant Campaign – Compromised Routers: The Record reports China’s Fire Ant hacking operation compromised Cisco routers as a platform for launching further attacks, undermining the trust layer those systems depend on [21].
ClickFix Social Engineering: The Hacker News reports that ClickFix remains a prevalent attack vector, with threat actors using deceptive web pages that place commands on visitors’ clipboards and talk them through opening terminals to paste and execute code [5].
METR Credential Theft – $numerous in AI Model Credit Abuse: Dark Reading reports security nonprofit METR had an API key stolen in an attack that led to $600,000 in unauthorized consumption of public AI model credits [20].
Ongoing: Earlier PaperCut NG/MF exploitation coverage continues; CISA added CVE-2026-82078 and CVE-2026-81578 to the Known Exploited Vulnerabilities catalog with federal remediation due September 14, 2026 [31, 32].
Today’s Action Checklist
- ☐ URGENT: Identify and patch all JFrog Artifactory instances; audit administrative token logs for compromise
- ☐ URGENT: Update Langflow deployments; rotate all exposed OpenAI and AWS API keys
- ☐ HIGH: Audit Composer dependencies for malicious PHP packages; review iOS app update compliance in user base
- ☐ HIGH: Alert development teams to recruiter phishing risks; deploy EDR across Linux and macOS workstations
- ☐ HIGH: Verify software supply-chain integrity; search package repositories for TeamPCP artifacts
- ☐ MEDIUM: Review CISA KEV additions (PaperCut CVE-2026-82078, CVE-2026-81578); confirm patches deployed by September 14
- ☐ MEDIUM: Monitor credential theft and healthcare sector breach notifications; review organizational exposure to Aesto/Novocure/Nutex systems