InfoSec News Nuggets – 09/02/2026
Brief
Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure
Threat actors have begun weaponizing a critical authentication-bypass flaw in JFrog Artifactory just days after its public disclosure, minting themselves administrator tokens on self-hosted instances left in their default configuration.
The flaw stems from a “phantom” join key that instances without an additional configured key receive, which attackers can forge to generate admin-level credentials and enumerate users, groups, and federated access setups.
Because Artifactory sits at the center of many software supply chains, researchers warn that admin access could let attackers tamper with build pipelines, move laterally into production, and push malicious changes downstream to customers.
