Actively exploited GitLab, Artifactory and browser flaws all have fixes — patch these first
Friday's reporting was dominated by vulnerabilities already under attack with patches available, alongside a run of AI-assisted intrusion campaigns.
CISA added a GitLab Community and Enterprise Edition path traversal vulnerability to its Known Exploited Vulnerabilities catalog on 11 September, based on evidence of active exploitation. The Hacker News reported that GitLab released patches for multiple flaws, including a maximum-severity path traversal vulnerability in the repository commits API that drew in-the-wild probes within hours of public disclosure. If you run self-managed GitLab, apply GitLab's fixed release now and review commits-API access logs for anomalous file reads.
The Register reported that further JFrog Artifactory bugs are under attack and that all three have patches, urging administrators to upgrade to a fixed version. BleepingComputer reported that threat actors are chaining critical and high-severity Artifactory flaws to bypass authentication, gain administrative privileges, and deploy a Rust backdoor on vulnerable self-hosted servers. Prioritise upgrading self-hosted Artifactory and hunt for unexpected admin accounts and unknown binaries.
Google's advisory lists Chrome releases earlier than 153.0.8010.36 as affected by several flaws. CISA's KEV catalog lists CVE-2026-87491 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, base 8.8) as known to be exploited; three further Chrome flaws — CVE-2026-87654, CVE-2026-87650 and CVE-2026-87646, each carrying the vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H, base 9.6 — are also fixed in 153.0.8010.36. Update Chrome to 153.0.8010.36 per Google's advisory.
CISA's KEV catalog also lists two Windows Server flaws as exploited: CVE-2026-85880 (vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, base 7.8), fixed in build 10.0.14393.9512, and CVE-2026-81963 (same vector and base 7.8), fixed in 10.0.26100.33438. Apply the Microsoft patches named in each advisory.
Among campaigns: Help Net Security reported that, according to GreyNoise, a threat actor built a PaperCut NG/MF exploit and used AI agents to compromise at least 440 instances across 395 organisations in 48 countries. BleepingComputer reported that Microsoft attributes passkey- and SSO-themed phishing that steals Microsoft 365 data to ShinyHunters, Helix and other extortion gangs. The Record and BleepingComputer reported Florida's DAVID driver database was breached using credentials belonging to a police department employee, a breach claimed by ShinyHunters. The Hacker News and BleepingComputer reported that Anthropic said it disrupted industrial-scale distillation attacks and other abuse of Claude. Treat AI-themed lures and passkey enrolment prompts as active phishing vectors and confirm reporting and credential-leak metrics, not just click rates, per SecurityWeek's phishing analysis.
Sources
- Schneier on Security — Friday Squid Blogging: Rotting Squid on a Beached California Boat
- BleepingComputer — Hackers abused Claude to extract secrets from 1.8M Android apps
- The Record — Florida says motor vehicle data breach tied to credentials stolen from officer’s personal device
- The Register — More JFrog Artifactory bugs under attack, and all 3 have patches
- SecurityWeek — Phishing Research Challenges Conventional Security Awareness Testing
- The Hacker News — GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure
- CISA — CISA Adds One Known Exploited Vulnerability to Catalog
- Help Net Security — AI agents exploited PaperCut flaws to breach 395 organizations
- BleepingComputer — Florida confirms DMV database breached via stolen police account
- The Record — Microsoft sees some new wrinkles in invoice-scam emails
- Schneier on Security — My Talk at DEF CON
- BleepingComputer — Passkey-themed phishing attacks lead to Microsoft 365 data theft
- BleepingComputer — Artifactory flaws chained in attacks deploying backdoor malware
- The Hacker News — Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks