Story thread · 4 reports / 4 sources
JFrog Artifactory Hacked in 24-Day Campaign; Rust Backdoors Survive Patching
techtimes.com · 2d

How the coverage leans
Across 4 sources · syndicated copies counted once
JFrog Artifactory vulnerabilities CVE-2026-42016, CVE-2026-42018, and CVE-2026-82329 were chained by multiple threat actors to hack build servers and plant Rust backdoors between August 15 and September 8, 2026. Patching removes entry paths but not attacker-created accounts or stolen credentials. Between 49-62% of self-hosted instances remain exposed.
First report: Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors — thehackernews.com, 4d
The coverage
- More JFrog Artifactory bugs under attack, and all 3 have patches
theregister.com · 3d
- Artifactory flaws chained in attacks deploying backdoor malware
bleepingcomputer.com · 3d
The conversation · 0
Sign in to join the conversation.
No comments yet — start the thread.