Threat actors are exploiting a newly patched critical security flaw in JFrog Artifactory to mint administrator tokens shortly after the vulnerability was disclosed.

Reader brief
No Reader read of this story yet.
So what3
Who is affected first and what likely follows, with a direction and a horizon. Extracted from the reports, never invented.
- JFrog Artifactory customers running unpatched versions (7.111.4–7.161.19 ranges) admin token minting· immediate
- Organizations using Artifactory for software supply chain supply chain compromise risk· days
- Security/DevOps teams patch and audit workload· days
Sources2
All filed from IndiaSingle originNamed United States · Artifactory · Berri · Kestra · Kludex · Sangoma · SonicWall · CISA · CVE.org · Google · Guillermo Rauch · Horizon3.ai · JFrog
- [1]The Hacker NewsneutralCISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners
- [2]The Hacker NewscriticalAttackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure