Hackers exploit critical JFrog Artifactory flaw to forge admin tokens
A critical authentication bypass flaw in JFrog Artifactory, tracked as CVE-2026-82329 and carrying a CVSS score of 9.8, is being actively exploited to mint fraudulent admin tokens on self-managed instances running in their default configuration. Researchers observed attackers gaining administrative permissions without authentication, a foothold that could let them enumerate users and groups, alter security settings, and poison software artifacts trusted by downstream CI/CD pipelines. The vendor patched the issue on August 28 across several version branches, but because access tokens remain valid independent of the binary upgrade, organizations need to actively revoke old tokens rather than assume patching alone closes the exposure.
Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code
Eight security flaws disclosed across seven command-line AI coding agents show that a repository’s own Git configuration can trigger command execution the moment an agent inspects it, often before any trust prompt is shown or the user has typed a single word. The issue centers on core.fsmonitor, a legitimate Git performance setting that agents query in the background to check branch and file status, letting a booby-trapped repository run code outside the tool’s sandbox and without approval. Fixes have shipped for goose, Claude Code, and Cursor, while Hermes Agent, Qwen Code, Grok Build, and a second execution path in Claude Code remained exploitable as of the most recent testing, underscoring how ordinary developer tooling plumbing has become a fresh attack surface for AI-assisted coding.
Critical SonicWall SMA 1000 Flaws Enable Unauthenticated RCE
Attackers are actively exploiting two newly disclosed zero-day vulnerabilities in SonicWall SMA 1000 series appliances that can be chained together for unauthenticated remote code execution. A maximum-severity server-side request forgery bug in the user-facing Work Place interface can be combined with a separate OS command injection flaw in the administrative console to hand an attacker full control of the device. SonicWall confirmed active exploitation in the wild and is urging customers running the affected 6210, 7210, and 8200v models to apply the released firmware immediately, check for indicators of compromise, and, if found, re-image hardware and reset all credentials, since these internet-facing edge devices have repeatedly proven attractive targets in recent years.
Extortion Group Claims Manchester Airports Group Data Breach
The extortion group FulcrumSec has claimed responsibility for stealing roughly 86 gigabytes of customer data from Manchester Airports Group, which owns Manchester, London Stansted, and East Midlands airports. The stolen information, pulled from a third-party-hosted database tied to car park, lounge, and Fast Track bookings as well as in-airport Wi-Fi sign-ups, includes email addresses, phone numbers, vehicle registrations, and postcodes, though no payment details were exposed. The airport operator refused a ransom demand, and while airport operations and passenger safety were unaffected, the group is reportedly moving to leak the data online after the failed extortion attempt.
Over 5,000 Dropbox accounts have been hacked, and the attackers only needed an email address
Roughly 5,000 Dropbox accounts were compromised after attackers discovered they could exploit a flaw in Lenovo’s email verification process to register a fraudulent Lenovo ID using nothing more than a victim’s email address, then use that identity to log into the associated Dropbox account without a password. The intrusion, which ran from August 4 to 21, succeeded largely because none of the affected accounts had two-factor authentication enabled, and in roughly a third of cases attackers viewed or downloaded stored files. Dropbox has since severed the Lenovo ID login integration, expired all sessions created through it, and now requires a Dropbox password even when signing in via Lenovo, while urging affected users to change passwords and enable multi-factor authentication.