Daily Briefing
Today's outlook
Actively exploited GitLab, Artifactory and browser flaws all have fixes — patch these first
Good morning. CISA added a GitLab Community and Enterprise Edition path traversal vulnerability to its Known Exploited Vulnerabilities catalog on 11 September, based on evidence of active exploitation. The Hacker News reported that GitLab released patches for multiple flaws, including a maximum-severity path traversal vulnerability in the repository commits API that drew in-the-wild probes within hours of public disclosure. If you run self-managed GitLab, apply GitLab's fixed release now and review commits-API access logs for anomalous file reads.
The Register reported that further JFrog Artifactory bugs are under attack and that all three have patches, urging administrators to upgrade to a fixed version. BleepingComputer reported that threat actors are chaining critical and high-severity Artifactory flaws to bypass authentication, gain administrative privileges, and deploy a Rust backdoor on vulnerable self-hosted servers. Prioritise upgrading self-hosted Artifactory and hunt for unexpected admin accounts and unknown binaries.
Google's advisory lists Chrome releases earlier than 153.0.8010.36 as affected by several flaws. CISA's KEV catalog lists CVE-2026-87491 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, base 8.8) as known to be exploited; three further Chrome flaws — CVE-2026-87654, CVE-2026-87650 and CVE-2026-87646, each carrying the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H, base 9.6 — are also fixed in 153.0.8010.36. Update Chrome to 153.0.8010.36 per Google's advisory.
CISA's KEV catalog also lists two Windows Server flaws as exploited: CVE-2026-85880 (vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, base 7.8), fixed in build 10.0.14393.9512, and CVE-2026-81963 (same vector and base 7.8), fixed in 10.0.26100.33438. Apply the Microsoft patches named in each advisory.
Among campaigns: Help Net Security reported that, according to GreyNoise, a threat actor built a PaperCut NG/MF exploit and used AI agents to compromise at least 440 instances across 395 organisations in 48 countries. BleepingComputer reported that Microsoft attributes passkey- and SSO-themed phishing that steals Microsoft 365 data to ShinyHunters, Helix and other extortion gangs. The Record and BleepingComputer reported Florida's DAVID driver database was breached using credentials belonging to a police department employee, a breach claimed by ShinyHunters. The Hacker News and BleepingComputer reported that Anthropic said it disrupted industrial-scale distillation attacks and other abuse of Claude. Treat AI-themed lures and passkey enrolment prompts as active phishing vectors and confirm reporting and credential-leak metrics, not just click rates, per SecurityWeek's phishing analysis.
Zoom out: Attackers' use of AI ran through the day — GreyNoise tied a PaperCut campaign to AI agents, Microsoft found AI-assisted invoice fraud, and Anthropic said it disrupted abuse of Claude.
Vulnerability in focus
CVE-2026-87491 — Google. CVSS 8.8 CISA lists it as known to be exploited.
Affected: chrome.
What to do: Follow the vendor advisory for the fixed release and any interim mitigation.
What we're tracking
- Schneier on Security: Friday Squid Blogging: Rotting Squid on a Beached California Boat Read it
- BleepingComputer: Hackers abused Claude to extract secrets from 1.8M Android apps Read it
- The Record: Florida says motor vehicle data breach tied to credentials stolen from officer’s personal device Read it
- The Register: More JFrog Artifactory bugs under attack, and all 3 have patches Read it
Sources
- Friday Squid Blogging: Rotting Squid on a Beached California Boat Schneier on Security
- Hackers abused Claude to extract secrets from 1.8M Android apps BleepingComputer
- Florida says motor vehicle data breach tied to credentials stolen from officer’s personal device The Record
- More JFrog Artifactory bugs under attack, and all 3 have patches The Register
- Phishing Research Challenges Conventional Security Awareness Testing SecurityWeek
- GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure The Hacker News
- CISA Adds One Known Exploited Vulnerability to Catalog CISA
- AI agents exploited PaperCut flaws to breach 395 organizations Help Net Security
- Florida confirms DMV database breached via stolen police account BleepingComputer
- Microsoft sees some new wrinkles in invoice-scam emails The Record
- My Talk at DEF CON Schneier on Security
- Passkey-themed phishing attacks lead to Microsoft 365 data theft BleepingComputer
- Artifactory flaws chained in attacks deploying backdoor malware BleepingComputer
- Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks The Hacker News
Summarized from the linked reports and the advisory record by the desk. Verify against the original sources before citing.