# Threat Intel Brief — September 2, 2026
TL;DR
- Critical zero-days under active exploit: Langflow (CVE-2026-0768) and JFrog Artifactory (CVE-2026-82329) are being weaponized for credential theft and admin token generation within days of disclosure.
- Supply chain attacks escalate: BGP hijacking delivered malicious Virtualizor updates; 13 malicious Composer packages targeted Vietnamese streaming sites to deploy iOS spyware and steal cryptocurrency wallets.
- Nation-state activity intensifies: Chinese Fire Ant compromised Cisco routers for espionage; Iranian Nimbus Manticore deployed cross-platform RATs via fake job offers; Russia-aligned UAC-0099 weaponized AI safety mechanisms to evade malware analysis.
- Massive identity breach: Over 153 million U.S. and Canadian driver's licenses sold on dark web following year-long exfiltration from Louisiana-based identity verification firm; FBI investigating.
- Healthcare sector under siege: Breaches at Aesto Health (9.5M records), Novocure (1,400+ cancer patients), and Berlin city administration (5.79 TB stolen) highlight persistent targeting of sensitive data.
---
Critical Threats
CVE-2026-0768: Langflow RCE Exploited for Cloud Credential Theft
What happened: Threat actors are actively exploiting CVE-2026-0768, an unauthenticated remote code execution vulnerability in Langflow AI development platform (CVSS 9.8). VulnCheck recorded 360+ attacks via honeypots, primarily from Russian infrastructure, targeting OpenAI API keys, AWS credentials, and Langflow superuser tokens. The flaw allows arbitrary Python code execution as root through improper input validation in the custom component editor's validate endpoint. Langflow versions 1.4.2 and earlier are affected; version 1.11.6 patches the issue.
Impact: Organizations using Langflow for AI workflows face immediate risk of credential compromise, cloud account takeover, and lateral movement into production environments. Langflow has been repeatedly exploited in 2026 (CVE-2026-33017, CVE-2026-5027, CVE-2026-55255, CVE-2026-0770, CVE-2026-9198), indicating sustained attacker interest in AI development infrastructure.
Recommendations:
- 0–24h: Upgrade all Langflow instances to version 1.11.6 immediately. Rotate all OpenAI API keys, AWS access keys, AWS secret keys, and Langflow superuser credentials. Review
/root/.cache/langflow/secret_key,.sshdirectories, and.bash_historyfor indicators of compromise. - 24–72h: Audit environment variables (LANGFLOW_SUPERUSER, OPENAI_API*, AWS_ACCESS*, AWS_SECRET*) and review logs for validate endpoint access from unauthorized sources, especially Russian IP ranges.
- This week: If immediate patching is not possible, restrict network access to Langflow instances to trusted IP ranges only.
---
CVE-2026-82329: JFrog Artifactory Auth Bypass Under Active Exploit
What happened: Attackers are exploiting CVE-2026-82329, a critical authentication bypass in JFrog Artifactory (CVSS 9.8), to generate administrative tokens under default configurations. watchTowr confirmed active exploitation as of September 1, 2026—just days after public disclosure on August 28. The flaw affects versions 7.161.0–7.161.19, 7.146.0–7.146.36, 7.133.0–7.133.28, 7.125.0–7.125.19, 7.117.0–7.117.27, and 7.111.4–7.111.21. Attackers are enumerating users, groups, and credential sets.
Impact: Unauthenticated attackers can obtain administrative privileges, enabling supply chain attacks including build pipeline tampering, binary poisoning, lateral movement to production systems, and downstream malicious code distribution to customers. No user interaction or authentication required.
Recommendations:
- 0–24h: Immediately upgrade self-managed JFrog Artifactory to version 7.161.20 or later patched versions. Inspect audit logs for unauthorized admin token generation, user enumeration, and suspicious access patterns since August 28, 2026.
- 24–72h: Rotate all JFrog Artifactory credentials, API keys, and access tokens, prioritizing administrative and service accounts. Review connected CI/CD pipelines, build systems, and downstream repositories for unauthorized changes, backdoors, or malicious artifacts.
- This week: Configure additional join keys on JFrog Access to eliminate phantom join key vulnerability in default configurations.
---
BGP Hijacking Delivers Malicious Virtualizor Updates
What happened: Hackers hijacked BGP routing for Virtualizor VPS management software's update infrastructure (hosted on Hetzner IP addresses) between August 28, 2026 (20:57 UTC) and August 30, 2026 (06:10 UTC). Fraudulent BGP routes redirected update requests to attacker-controlled servers delivering backdoored updates. A malicious systemd service (java-jre-update.service) was deployed to compromised systems. Softaculous client portal credentials and payment information entered during the 33-hour window are also at risk.
Impact: Hosting providers using Virtualizor for VPS management may have received backdoored updates establishing persistent access via malicious systemd services. Compromised systems likely exposed API credentials, SSH keys, and potentially customer data. Vendor lacks logs of affected systems due to traffic redirection. Supply chain attack vector bypassed traditional security controls by impersonating legitimate update mechanism.
Recommendations:
- 0–24h: Check all Virtualizor servers for
/etc/systemd/system/java-jre-update.service; if present, assume full compromise and initiate incident response. Update to Virtualizor 3.2.9.9 immediately and run the new Security Analyzer tool from the admin panel. - 24–72h: Rotate all Virtualizor API credentials, audit for unauthorized SSH keys, user accounts, cron jobs, and suspicious outbound network connections. Reset passwords for any Softaculous client portal accounts accessed between August 28 20:57 UTC and August 30 06:10 UTC; monitor payment card statements for fraud.
- This week: Review BGP monitoring and RPKI validation capabilities with upstream providers to detect future route hijacking attempts.
---
153 Million Driver's Licenses Sold on Dark Web
What happened: A dark web identity theft service called "Nexus" is selling digital scans of over 153 million driver's licenses from the United States and Canada, allegedly sourced from a Louisiana-based identity verification company. The breach includes standard, infrared, and ultraviolet images with timestamps, plus commercial driver's licenses, Common Access Cards (CAC), marijuana dispensary cards, and medical cards. The actor claims continuous exfiltration for over 12 months, with approximately 400,000 new records added within a 24-hour period. High-profile targets include U.S. Defense Secretary Pete Hegseth. The FBI's New Orleans field office has launched an official investigation.
Impact: Over 153 million individuals face immediate risk of identity theft, synthetic identity fraud, and account takeover. Organizations using third-party identity verification services face supply chain exposure. The presence of government officials' credentials and potential CAC data creates national security concerns. Continuous 12-month exfiltration indicates persistent, undetected access to production identity verification systems.
Recommendations:
- 0–24h: Organizations using third-party identity verification services should demand immediate breach notification and conduct security assessments of vendor relationships. Monitor dark web marketplaces for organizational data exposure.
- 24–72h: Implement real-time monitoring for bulk data access patterns and unusual query volumes in identity verification databases. Deploy data loss prevention (DLP) controls to detect exfiltration of image files with identity document characteristics.
- This week: Implement strict access controls and audit logging for identity verification databases, with alerts for privileged account usage, API abuse, or access patterns inconsistent with legitimate business operations. Validate log timestamps against external time sources to detect timestamp manipulation.
---
Threat Actor Activity
Fire Ant (China): Cisco Router Compromise for Network Surveillance
Chinese espionage actor Fire Ant (overlaps with UNC3886) has expanded operations beyond VMware hypervisors to compromise Cisco IOS XR routers, TACACS authentication servers, and Linux management hosts. The group creates unexplained GRE tunnel interfaces on routers for covert communications, deploys custom malware with fake system services executing during alternating hours, and selectively suppresses syslog messages to hide tunnel-related activity. The BridgeAgent backdoor masquerades as legitimate Zabbix monitoring agents with systemd persistence. Attackers capture network traffic via PCAP and exfiltrate to external FTP servers. The "target behind the target" strategy uses compromised trusted infrastructure as bridges into high-value networks.
Defensive priorities: Monitor Cisco IOS XR routers for unexplained GRE tunnel interfaces lacking configuration entries. Detect selective syslog suppression by comparing output against expected baseline volumes. Hunt for fake systemd services with temporal execution patterns. Monitor for outbound Telnet connections from network infrastructure devices and PCAP file uploads to external FTP servers. Implement file integrity monitoring to detect timestamp manipulation.
---
Breeze Comet (Brazil): Payment System Fraud Campaign
Breeze Comet (formerly UNC5669) has been targeting Brazilian financial services, retail, and e-commerce organizations since 2024 to conduct fraudulent transactions through manipulation of Pix, STR, and Boleto payment systems. The campaign has resulted in hundreds of fraudulent transfers across Brazilian payment systems. The group uses password spraying, social engineering via WhatsApp impersonating IT support, exploitation of vulnerable JBoss AS servers, and compromised Brazilian government websites for staging malware. Custom malware suite includes COBALTSPIN (Rust-based SOCKS5 proxy), LIGHTPAINT (Java backdoor installing SoftEther VPN), MILDFROST (passive Java backdoor with DNS tunneling), KICKPLATE (Nim backdoor impersonating Windows Update), and BOATBEAM (Golang backdoor with fake IIS HTTPS server). Recent infrastructure indicates potential expansion into Paraguay, Venezuela, Nigeria, and Ghana.
Defensive priorities: Monitor for unauthorized RMM tool installations (AnyDesk, SoftEther VPN). Deploy detection rules for custom malware indicators. Implement robust monitoring of privileged account usage in financial API systems, particularly for Pix, STR, and Boleto platforms. Harden JBoss AS servers and deploy web application firewalls. Enable tamper protection for endpoint security solutions.
---
Nimbus Manticore (Iran): Cross-Platform RATs via Fake Job Offers
Iranian threat actor Nimbus Manticore (also tracked as Iranian Dream Job) has deployed two previously undocumented cross-platform RAT malware families (NodeRabbit, PollCat) developed using Node.js and JavaScript, targeting Linux and macOS systems through social engineering tactics posing as recruiters with coding tests. Malicious ZIP archives contain trojanized npm packages (colorized_terminal, pretty-log) that deploy RATs with persistence via Windows Run registry keys, cron entries on Linux, and launch agents on macOS. C2 communication via Azure-hosted infrastructure. Capabilities include command execution, file operations, process enumeration, network adapter discovery, credential harvesting from Outlook artifacts, and anti-analysis checks. Advanced variants support WSL-specific persistence via scheduled tasks and fake VS Code extension installation. Observed infections span Afghanistan, Egypt, and Ethiopia.
Defensive priorities: Monitor for suspicious npm packages bundled in node_modules directories rather than fetched from official registries. Detect Registry Run Keys and Launch Agent persistence. Implement behavioral detection for Node.js processes spawning detached background processes from hidden cache directories. Block or alert on outbound connections to Azure-hosted C2 domains using API endpoints matching patterns /api/rabbit/* or /sdk/v2/*. Hunt for WSL-specific persistence mechanisms including daily scheduled tasks executing VBScript files via wscript.exe and wsl.exe.
---
UAC-0099 (Russia): GuardBreaker Anti-AI Analysis Technique
Russia-aligned threat actor UAC-0099 has deployed GuardBreaker, a technique that embeds adversarial prompt injections (nuclear weapon construction prompts) as comments in VBS scripts to trigger LLM safety mechanisms and prevent AI-assisted malware analysis. The group uses VBS scripts for initial payload delivery, downloading and installing MATCHBOIL, a custom C# loader for second-stage payload deployment. In July 2026, CERT-UA observed UAC-0099 masquerading malware as legitimate Notepad++ plugins to compromise Windows systems. The actor demonstrates awareness of modern security workflows and actively adapts tactics to evade AI-powered detection systems. Targets include Ukrainian organizations within technology and defense sectors.
Defensive priorities: Implement content isolation in AI-assisted analysis pipelines to treat all analyzed code as untrusted data. Deploy multi-layered detection that does not rely solely on AI/LLM-based triage. Monitor for VBS script execution via Windows Script Host. Detect masquerading attempts by validating digital signatures of plugins and extensions. Hunt for MATCHBOIL C# loader indicators including network connections to known UAC-0099 infrastructure.
---
North Korea: IT Worker Scheme Expands Beyond IT Roles
North Korean threat actors (tracked as Famous Chollima, Jasper Sleet, Nickel Tapestry, PurpleDelta, UNC5267, Wagemole) have expanded their job fraud scheme beyond IT roles into healthcare, biotechnology, sales, and marketing sectors. Between late 2024 and early 2025, one cluster applied to jobs at over 1,100 companies globally. The campaign uses stolen/forged identity documents, AI-generated synthetic personas via TrustID Card, VPNs (Astrill VPN), proxy services (IPRoyal Proxy), KVM switches (PiKVM, TinyPilot), and USB capture cards (Guermok) to connect to laptop farms. During interviews, actors deploy screen recording software, AI transcription tools, and ChatGPT to generate real-time answers. Specific cases include three suspected North Korean workers employed at an Australian healthcare company impersonating Chinese individuals.
Defensive priorities: Implement rigorous identity verification during hiring, including reverse image searches of candidate photos and verification of identity documents against known fraud patterns. Monitor for anomalous VPN and proxy usage patterns during onboarding and employment. Detect unauthorized hardware installations by monitoring for KVM switches and USB capture devices through EDR tools. Flag suspicious interview behaviors including verbatim repetition of AI-generated responses. Conduct enhanced background checks including online presence verification and social media validation.
---
Geopolitical Context
Latvia's Cyber Threat Level Remains High: CERT.LV reports that Latvia's cybersecurity threat level remains elevated in Q2 2026, with cyber incidents sixfold higher and compromised devices eightfold higher than pre-2022 baselines. Russia is identified as "the main source of cyber threats to Latvia," with activities of Russia-backed cyber attackers and hacktivists likely to continue in response to Latvia's support for Ukraine. The sustained threat environment has driven institutional adaptation, including expanded SOC coverage and DNS firewall deployment blocking over 5 million malicious access attempts in H1 2026.
Chinese Espionage Targets U.S. Federal Agencies: The U.S. Department of Justice corrected a previous statement regarding Chinese threat actor QTFY, clarifying that multiple U.S. federal agencies including NASA, the Federal Reserve, Department of Energy, and Department of Justice were targeted rather than confirmed as victims of successful breaches. QTFY, linked to Nanjing Xinjiuwei Network Technology Co. and allegedly operating on behalf of China's Ministry of State Security, has been active since 2018. The FBI disrupted QTFY infrastructure by seizing domains associated with QScan and QTRouter tools.
Berlin Ransomware Attack: Berlin's city administration confirmed data theft following a Rhysida ransomware attack, with threat actors claiming exfiltration of 5.79 TB across 1.44 million files between August 7–12, 2026. Stolen data includes personnel records, financial information, critical infrastructure assessments (Berlin water supply security), and classified government materials. Berlin refused to pay the ransom, aligning with German federal policy discouraging ransom payments.
---
Recommended Actions
0–24 Hours (Immediate)
- Upgrade Langflow to version 1.11.6 and rotate all OpenAI API keys, AWS credentials, and Langflow superuser tokens.
- Upgrade JFrog Artifactory to version 7.161.20 or later and rotate all credentials, API keys, and access tokens.
- Check all Virtualizor servers for malicious systemd service (
java-jre-update.service); if present, initiate incident response. - Apply PaperCut Emergency Patch Release 3 to all NG and MF Application Servers and remove from direct internet exposure.
- Organizations using third-party identity verification services should demand immediate breach notification following the 153M driver's license breach.
24–72 Hours
- Audit Langflow and JFrog Artifactory logs for indicators of compromise since August 28, 2026.
- Rotate Virtualizor API credentials and audit for unauthorized SSH keys, user accounts, and cron jobs.
- Review PaperCut-published indicators of compromise and search logs for authentication anomalies and Derby database access patterns since August 29, 2026.
- Implement real-time monitoring for bulk data access patterns in identity verification databases.
This Week
- If immediate Langflow patching is not possible, restrict network access to trusted IP ranges only.
- Configure additional join keys on JFrog Access to eliminate phantom join key vulnerability.
- Review BGP monitoring and RPKI validation capabilities with upstream providers.
- Monitor Cisco IOS XR routers for unexplained GRE tunnel interfaces and configuration anomalies.
- Implement enhanced identity verification during hiring processes to detect North Korean IT worker fraud.
---
Watch List
- Ruby on Rails CVE-2026-66066: Active exploitation confirmed alongside Langflow. Affects applications using libvips for Active Storage image processing that accept untrusted image uploads. Update to Rails 8.1.3.1, but note the patch does not fully mitigate RCE via Marshal deserialization.
- Microsoft Exchange CVE-2026-62911: Nearly 22,000 internet-exposed servers remain unpatched against authentication bypass vulnerability allowing mailbox hijacking. Public exploit code available; no confirmed active exploitation yet.
- PaperCut CVE-2026-81578 and CVE-2026-82078: Zero-days under active exploitation for data theft via authentication bypass and RCE. Over 800 servers currently exposed online.
- ClickFix/TerminalFix: Social engineering technique identified as most common initial access method by Microsoft (47% of attacks). New variant uses fake Cloudflare CAPTCHA prompts to trick victims into executing malicious PowerShell commands via Windows Terminal.
- Malicious Composer Packages: 13 packages on Packagist inject JavaScript into Vietnamese streaming sites to deploy iOS spyware (exploiting CVE-2025-31277, CVE-2025-43529) and steal cryptocurrency wallet seeds.
---
Sources
- BleepingComputer: Critical Langflow flaw exploited to steal OpenAI and AWS keys
- The Hacker News: Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure
- BleepingComputer: Hackers push malicious Virtualizor update in BGP hijacking attack
- Krebs on Security: FBI Probes Service Selling 153M+ Drivers Licenses
- BleepingComputer: Recently patched PaperCut zero-days used in data theft attacks
- The Hacker News: Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity
- BleepingComputer: Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks
- BleepingComputer: Chinese Fire Ant hackers turn Cisco routers into spying platforms
- The Hacker News: Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems
- The Hacker News: Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests
- The Hacker News: Russia-Aligned UAC-0099 Plants Nuclear Weapon Prompt in Malware to Disrupt AI Analysis
- The Hacker News: North Korean Job Fraud Expands Beyond IT Into Healthcare and Sales
- CERT.LV: CERT.LV activity review Q2 2026
- The Hacker News: DoJ Corrects China Hacking Claim, Says U.S. Agencies Were Targets, Not Victims
- BleepingComputer: Berlin confirms data theft after Rhysida ransomware attack claims
- Microsoft Security: Counterfeit installers to system compromise: Tracking a deceptive software download campaign
- Unit 42 (Palo Alto): Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams
