This day 02:08 06:08 10:08 14:09 18:10 22:00
⚠ exploit status: CVE-2026-82329 · KEV
Info  2026-09-02 10:08Z · last 4h · 21 findings · glm-5.2:cloud

Threat Brief — 2026-09-02: Fixes Fail, Monitors Fall Silent

A second unauthenticated vulnerability has surfaced in JFrog Artifactory just days after the original flaw was disclosed and patched, suggesting attackers are actively mining the same code path for related bugs. Boston Scientific's ongoing cyberattack fallout has now knocked cardiac monitoring devices offline for a week, forcing clinicians back to manual checks. Elsewhere, a Harvard study demonstrates how commercial ad-surveillance infrastructure routinely exposes journalists' movements and sources, and Russia's digital ministry is preparing expanded smartphone access for AI systems.

Top items

Themes

Fixes that don't fix. The JFrog Artifactory development is the second instance this week where a vendor shipped a patch that failed to fully close the attack path, echoing the pattern seen with SonicWall SMA1000 zero-days still under active exploitation. Patch-and-verify cycles need to account for clustered vulnerabilities in the same code paths.

AI as both target and tool. The Fable prompt leak, the SIR red-teaming paper, and Russia's expanded AI-access plans all point in different directions at the same trend: AI systems are simultaneously the object of attack (prompt exfiltration, agent exploitation) and a vector for expanded access to sensitive systems.

Healthcare operational fallout deepening. Boston Scientific's telemetry outage moves the impact from supply-chain disruption into direct patient-care territory — a reminder that cyberattack consequences in healthcare extend well beyond data theft.

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db