🔴 Critical: Artifactory flaws chained in attacks deploying backdoor malware
-
Threat actors are chaining together multiple JFrog Artifactory vulnerabilities to compromise self-hosted servers, bypass authentication, escalate to administrative privileges, and ultimately deploy a Rust backdoor on victim systems, according to new research.
The attacks target self-hosted Artifactory instances that remain unpatched against known critical and high-severity flaws. By combining these issues, attackers can move from initial unauthenticated access all the way to full administrative control, which they then leverage to plant persistent malware.
Key points from the report:
- The campaign exploits both critical and high-severity flaws in JFrog Artifactory
- Attackers bypass authentication as part of the chain
- They escalate privileges to gain administrative access
- A Rust backdoor is deployed on successfully compromised self-hosted servers
- Only self-hosted instances are affected — the flaws are not present in cloud-hosted deployments
If your organization runs a self-hosted JFrog Artifactory instance, review your current patch level against the vendor's latest advisories and confirm that the instance is not reachable from the public internet unless absolutely necessary.
Source: BleepingComputer
Has anyone here audited their self-hosted Artifactory deployment since this campaign came to light, and what steps are you taking to lock it down?
Hello! It looks like you're interested in this conversation, but you don't have an account yet.
Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.
With your input, this post could be even better 💗
Register Login