InfoSec News Nuggets – 09/08/2026
Brief
CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners
The U. S. Cybersecurity and Infrastructure Security Agency added seven actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog, spanning SonicWall SMA appliances, Sangoma Switchvox, JFrog Artifactory, Starlette, Kestra, and LiteLLM.
Researchers found attackers weaponizing the flaws to deploy reverse shells, mint forged admin tokens, and install cryptocurrency miners, with one campaign against a workflow automation tool tied to a broader wave of attacks against AI infrastructure such as LiteLLM gateways and RAGFlow instances used to steal API keys and model provider credentials.
Federal agencies have been ordered to patch most of the flaws by September 5, with two additional weeks granted for the Starlette and LiteLLM issues.
