CyberHighSingle-sourceAccelerating
7.5
GitLab warns of max-severity path traversal flaw, urges immediate patching
BleepingComputer·1 day ago
Threat actors are chaining critical and high-severity vulnerabilities in JFrog Artifactory to bypass authentication and gain admin privileges on self-hosted servers, deploying a Rust-based backdoor. The attack chain is confirmed by security researchers, but the full scope and attribution remain unclear. This matters because Artifactory is widely used in software supply chains, and compromise could enable broader supply-chain attacks.