> InfoSec News Nuggets – 09/11/2026
[AUTHOR: Mary]
[DATE: 11/09/2026 10:50]
[LANGUAGE: EN]
Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329
Wiz Research identified active exploitation of three JFrog Artifactory vulnerabilities that attackers are chaining to bypass authentication and gain full administrative control of self-hosted repository servers between August 15 and September 8. One chain combines an authentication flaw that improperly hands out an internal anonymous-user token with a token-scope validation bug that lets attackers swap it for admin-level access, while a separate critical flaw, CVE-2026-82329, offers unauthenticated attackers a direct path to admin privileges via a single crafted request to the registry-join endpoint. Post-compromise activity included creating persistent administrator accounts, deploying malicious Groovy plugins for arbitrary code execution, and installing custom Rust-based backdoors — a serious supply chain risk given that Artifactory typically stores proprietary software packages, build credentials, and CI/CD integration secrets used across development pipelines.
New ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft Defender
Security researcher Nightmare Eclipse published ShieldCrash, a proof-of-concept exploit that bypasses Microsoft’s patch for ShieldBreak — itself a bypass for an earlier Defender flaw called RoguePlanet — marking the third consecutive patch-bypass exploit against the same Microsoft Malware Protection Engine component. The published PoC demonstrates an arbitrary file read with SYSTEM privileges on fully patched Windows 10, 11, and Server systems following September’s Patch Tuesday, though the researcher says the underlying flaw could be extended to dump the SAM database for full SYSTEM access. This is the researcher’s fifteenth uncoordinated disclosure since April, and while Microsoft has not yet publicly acknowledged ShieldCrash or assigned it a CVE, the recurring pattern of successive patches getting bypassed suggests the underlying architectural weakness in Defender’s remediation engine hasn’t actually been resolved.
MantaxOtax Android Malware Combines Ransomware With Spyware
Zimperium’s zLabs team detailed MantaxOtax, an Android malware strain linked to Indonesian threat actors that combines file-encrypting ransomware with extensive surveillance capabilities, distributed via sideloaded APKs on third-party file-sharing services rather than Google Play. After requesting device administrator privileges followed by SMS, contacts, media, and Accessibility service access, the malware gains near-total control over the device — intercepting SMS-based one-time passwords, harvesting WhatsApp and Telegram messages, silently capturing camera photos and screen recordings, and resolving its command-and-control domain from a GitHub repository so operators can swap infrastructure without recompiling. The ransomware component only fully functions on Android 9 and earlier due to newer Scoped Storage protections, but the surveillance and credential-theft capabilities work across versions, enabling double-extortion tactics even against modern devices where file encryption is limited.
CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline
CISA added three actively exploited vulnerabilities affecting Cisco, Citrix, and Fortinet to its Known Exploited Vulnerabilities catalog, giving federal agencies until September 12 to patch. The most severe, CVE-2026-20079 (CVSS 10.0), is an authentication bypass in Cisco Secure Firewall Management Center that lets unauthenticated attackers execute scripts and gain root access, with Cisco confirming exploitation dates back to August; CVE-2026-19490 (CVSS 9.3) affects Citrix NetScaler ADC and Gateway appliances and has seen a documented surge in honeypot exploitation attempts since September 3. The third flaw, a Fortinet heap-based buffer overflow, is tied to a campaign deploying a feature-rich Node.js remote access trojan called PivotC2 on compromised FortiGate devices, which supports interactive shells, proxy tunneling, network scanning, and FortiGate-specific credential decryption.
Hackers Drain $320 Million From Liquid Network, Then Return Most of It
Attackers exploited a range-proof verification bug in Elements, the software underpinning Blockstream’s Liquid Network Bitcoin sidechain, to drain roughly 4,000 BTC — nearly 95% of the federation wallet’s reserves — worth about $320 million at the time, without compromising any of the cryptographic keys that secure the multisig wallet itself. The attackers identified themselves as white-hat hackers, communicated with Blockstream via on-chain OP_RETURN messages, and returned approximately 3,400 BTC after confirming the affected bridge nodes had been patched, keeping roughly 598 BTC (about $47 million) as a self-appointed bounty. The incident highlights a structural risk in federated sidechain architectures: even with hardware-secured multisig keys never compromised, a subtle logic flaw in the underlying verification code was enough to let an attacker mint and redeem far more L-BTC than the reserve actually backed.
The post InfoSec News Nuggets – 09/11/2026 appeared first on AboutDFIR - The Definitive Compendium Project.