AI安全专题周报(20260911)
报告编号:TIC-202609-AI02
报告周期:2026年9月5日—9月11日
一、报告概述基于360威胁情报中心对本期公开网络安全素材的整
报告编号:TIC-202609-AI02
报告周期:2026年9月5日—9月11日
一、报告概述基于360威胁情报中心对本期公开网络安全素材的整
A threat actor built a working exploit for PaperCut print management software, then handed the job of breaking into hundreds of organizations to AI agents that did most of the work on their own, according to GreyNoise. The result was at least 440 compromised PaperCut instances across 395 identified organizations in 48 countries. Attacker, believed to be Russian-speaking, first built a private lab environment with a vulnerable copy of PaperCut NG/MF and an Active Directory … More →
The post AI agents exploited PaperCut flaws to breach 395 organizations appeared first on Help Net Security.
Threat actors are actively exploiting three vulnerabilities in JFrog Artifactory, CVE-2026-42016, CVE-2026-42018, and CVE-2026-82329, to bypass authentication, escalate privileges, and gain administrative control of exposed instances. Wiz Research reports that multiple attackers are targeting self-hosted Artifactory deployments in the wild, using both a two-bug token escalation chain and a separate critical authentication-bypass flaw. A successful […]
The post Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Okta has released security updates for three high-severity vulnerabilities affecting the Auth0 AD/LDAP Connector and Okta Access Gateway. These vulnerabilities could allow authenticated attackers to trigger stored cross-site scripting (XSS), bypass Protected Rule authorization controls, or execute unintended SQL commands against configured backend databases under specific deployment conditions. All three vulnerabilities were disclosed on September […]
The post Okta Patches Auth0 and Access Gateway Vulnerabilities Let Attackers Enable XSS, Authentication Bypass and SQL Injection appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.