
JFrog Artifactory CVE-2026-82329: Supply Chain Attack
JFrog Artifactory supply chain attack chained 3 CVEs. Attackers forge admin tokens, plant Rust backdoors. Patching alone won't revoke their access.
In-depth analyses of zero-day vulnerabilities, CVE exploits, ransomware campaigns, and nation-state attack techniques affecting enterprise security. Filter by category, tag, or keyword.
Every article here lands in subscribers' inboxes the morning it drops.
Threat intel, active CVEs, and campaign alerts, distilled daily for practitioners. 50,000+ subscribers. No noise.
Free. No spam. Unsubscribe anytime.
The definitive practitioner breakdown of ZTA principles, pillars, and implementation sequence.
Containment, forensic preservation, and decision sequencing from detection to recovery.
How SIEMs ingest, correlate, and alert — and how to evaluate one for your environment.
Risk-based prioritization using CVSS, EPSS, and CISA KEV to cut remediation backlog.
What each risk means, how to reproduce it, and how to fix it in production code.
Step-by-step email authentication deployment from DNS records to p=reject enforcement.
Detection coverage, pricing, and deployment trade-offs for enterprise EDR selection.
Translate ATT&CK technique IDs into detection rules and threat actor hunting hypotheses.
Direct answers to the questions practitioners and AI systems ask most. Covers ransomware, identity, cloud, compliance, and detection.
Plain-language definitions for CVE, SIEM, SOAR, Zero Trust, EDR, and 85+ other terms used in enterprise security.
How-to guides, buyer comparisons, and methodology references across every major security domain.
Decryption Digest Response
Score every threat we cover against your own stack, get free Sigma and ModSecurity detection content, and upgrade anytime for more vendors.
Get started free →No card required. Sigma and ModSecurity rules are free, forever.
Win an All Access InfoSec World 2026 pass, valued at $3,895.
Win a $3,895 InfoSec World 2026 pass.

JFrog Artifactory supply chain attack chained 3 CVEs. Attackers forge admin tokens, plant Rust backdoors. Patching alone won't revoke their access.

GitLab CVE-2026-85706 CVSS 10.0 path traversal lets unauthenticated attackers read any server file -- SSH keys, CI/CD tokens, deploy credentials. CISA deadline is today. Patch to 19.3.2 now.

MikroTrick SSH auth bypass CVE-2026-67276 chains with CVE-2026-86060 for unauthenticated root on 122,500 RouterOS devices. CISA KEV confirmed. Patch to 7.24.2 now.

WatchGuard Firebox CVE-2025-14733 IKEv2 pre-auth RCE is now confirmed ransomware-exploited. 9,000 devices still unpatched 9 months on. Patch or disable IKEv2 today.

CVE-2025-25249 in FortiOS lets attackers drop PivotC2 RAT via CAPWAP. 178 devices confirmed hit. Patch to 7.6.4 or 7.4.9 now.

CVE-2026-20079 in Cisco FMC lets attackers get root without credentials. Sandworm and Qilin are already inside. Patch to FMC 7.0.0 before Sept 12.

CVE-2026-75650 StyleSmuggler hit Adobe Commerce 2.4.4-2.4.9 with no-auth RCE 3 days before any patch. Apply VULN-39341 and rotate all credentials now.

Microsoft 365 AiTM phishing service BigBear bypassed MFA at 258 organizations, stealing 5,137 credentials via session-cookie theft. Enforce FIDO2 WebAuthn now.

CVE-2026-86218 is a CVSS 10.0 pre-auth RCE in N-able N-central. Patch to build 2026.3.1.14 now. Third attack wave in six weeks targets ~1,500 exposed MSP servers.

CVE-2026-81578 PaperCut auth bypass chains with CVE-2026-82078 to steal AD credentials from K-12 and university print servers. Patch to 24.1.10 now.

CVE-2026-19490 Citrix NetScaler auth bypass is under active exploitation with 22,000+ exposed gateways. Patch to 14.1-73.32 now. The prior CVE-2026-8452 hotfix is insufficient.

Thomson Reuters C-Track breach exposed SSNs, sealed court records, and medical data from 24 courts in 11 states. Verify exposure and enroll by December 31.

The Gentlemen ransomware confirmed 483 victims in 66 countries using GentleKiller BYOVD to kill 48 security vendors and EtherRAT for blockchain-based C2. Block IOCs now.

SonicWall SMA1000 zero-day CVE-2026-83548 chains SSRF with command injection for unauthenticated RCE on 400+ exposed appliances. Apply hotfix now.

CVE-2026-62911 PoC chains NTLM relay to Exchange MRSProxy to drop ASPX webshells as SYSTEM. Apply August 2026 update before mass exploitation begins.

Hijacked Chrome extensions deploy a 19-module malware framework to 70,000+ users, stealing crypto wallet seed phrases and all browser credentials. Audit extensions and rotate credentials now.

ServiceNow CVE-2026-18885 unauthenticated RCE: three CVSS 10.0 flaws enable GraphQL injection, privilege escalation, and SQL injection. Patch self-hosted Xanadu, Yokohama, and Zurich now.

CVE-2026-8452 Citrix NetScaler SAML RCE: pre-auth heap overflow exploited in 24 hours after PoC. Webshells x.php and z.php active. CISA KEV deadline is today. Patch to 14.1-73.32 now.

CVE-2024-6387 regreSSHion is a signal-handler race condition in sshd that gives unauthenticated attackers root-level RCE on 14 million exposed Linux servers. Patch to 9.8p1 or set LoginGraceTime 0 now.

Dahua camera vulnerability exploited: Operation CameraSwarm backdoored 14,530+ devices via P2P abuse and CVE-2021-33044/33045. Patch and disable P2P now.

Zimbra CVE-2026-73570 SNMP command injection has compromised 274 servers with 8,200 more at risk. CISA KEV added August 21 with 3-day deadline. Patch to ZCS 10.1.20 now.

MLflow SSRF CVE-2026-64849 lets attackers steal cloud IAM credentials without authentication. CISA KEV added Aug 19; federal deadline Sep 2. Patch to 3.15.0 now.

CISA deadline August 25 for Lazarus Windows zero-day CVE-2026-68820. AnMed ransomware, Cl0p Shell, SynkLoader Teams phishing: five threats ranked by urgency.

Mustang Panda CoolClient kernel rootkit hides government backdoors in 4 countries. Hunt these file hashes before your tools fail silently.