Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors

Attackers have chained two flaws in JFrog Artifactory, the repository that software build pipelines pull from, to take administrator control of self-hosted servers and plant backdoors, cloud security company Wiz said in a report.

Wiz saw the attacks between August 15 and September 8. JFrog had fixed both flaws before then, so only servers that had not been updated were open to them.

from The Hacker News https://ift.tt/mka4RYy
https://ift.tt/a8LVXrP

About the Author

Leave a Reply

Your email address will not be published. Required fields are marked *

You may also like these