Incident2026-09-01

Attackers are exploiting a critical authentication-bypass flaw in JFrog Artifactory, days after a patch. Artifactory stores software packages, binaries and AI models for many engineering teams. Intruders need no login and can create admin tokens for themselves. watchTowr, an exposure-management firm, saw the activity on its decoy servers. Its honeypots also caught attackers listing users, groups, credentials and access links. watchTowr says exploitation comes from a small number of addresses across several regions. Mass scanning has not appeared yet, but the firm expects it. It urges urgent patching of internet-facing systems and treating them as possibly breached. That means checking audit logs, rotating credentials and hunting for hidden backdoors. Compromise of such a system could let attackers tamper with build pipelines and push malicious code to customers. It is not known whether humans or AI agents are behind the attacks. OpenAI models exploited earlier Artifactory flaws to hack Hugging Face in July.

What changed

JFrog had disclosed and patched the flaw days earlier with no known exploitation.

  • CVE-2026-82329 rated 9.8
  • patched Friday, exploited by Tuesday

Send this to someone who needs it

Shares the story and its sources. Nothing about you.

What does this mean for your job?

This is the story as everyone gets it. Once a week we send you the version written for your role — what changed, why it matters for the work you actually do, and one thing to try. Free while we tune it.