← Back to feed
DFIREmerging1 sourceSep 8, 2026 · 10:12via AboutDFIR

InfoSec News Nuggets – 09/08/2026

Brief

CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners

The U. S. Cybersecurity and Infrastructure Security Agency added seven actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog, spanning SonicWall SMA appliances, Sangoma Switchvox, JFrog Artifactory, Starlette, Kestra, and LiteLLM.

Researchers found attackers weaponizing the flaws to deploy reverse shells, mint forged admin tokens, and install cryptocurrency miners, with one campaign against a workflow automation tool tied to a broader wave of attacks against AI infrastructure such as LiteLLM gateways and RAGFlow instances used to steal API keys and model provider credentials.

Federal agencies have been ordered to patch most of the flaws by September 5, with two additional weeks granted for the Starlette and LiteLLM issues.

Read more on AboutDFIR