Skip to content
Artwork for You've Already Been Hacked
You've Already Been Hacked · September 7 · 31 min

Artifactory's Backdoor: Why Patching Isn't Enough

Hosts * Professor CyberRisk * Cyber Cowboy Live Cyber Maps * Bitdefender Threat Map: https://threatmap.bitdefender.com/ * Checkpoint Threat Map: https://threatmap.checkpoint.com/ * Kaspersky Cyber Threat Map: https://cybermap.kaspersky.com/ * Talos Intelligence - ebc_spam Map: https://talosintelligence.com/ebc_spam Episode Information Title: Artifactory's Backdoor: Why Patching Isn't Enough Episode Number: 3x61 Overview Weekly roundup of the most critical cybersecurity developments from 2026-08-30 to 2026-09-03. Join Professor CyberRisk and Cyber Cowboy Live as they break down the stories that matter most. Guest Information None this episode Topics Covered * Software supply-chain poisoning via forged admin tokens (CVE-2026-82329) * Mass-exposed Exchange servers and mailbox hijack (CVE-2026-62911) * GDPR enforcement: French hospital fined €500,000 after 727,000-record breach * Stealthit infostealer abusing Node.js Single Executable Applications Top Stories 1. Hackers exploit critical JFrog Artifactory flaw to forge admin tokens - https://www.bleepingcomputer.com/news/security/hackers-exploit-critical-jfrog-artifactory-flaw-to-forge-admin-tokens/ Additional Cybersecurity News – Titles and URLs 2. Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks - https://www.bleepingcomputer.com/news/security/nearly-22-000-microsoft-exchange-servers-vulnerable-to-hijack-attacks/ 3. French hospital fined €500,000 after breach exposes data of 727,000 - https://www.bleepingcomputer.com/news/security/french-hospital-fined-500-000-after-breach-exposes-data-of-727-000/ 4. Stealthit infostealer gets a Node.js makeover — fake games and VPNs are the bait - https://hoploninfosec.com/stealit-malware-attacks Resources & Links * JFrog security advisories: https://docs.jfrog.com/releases/docs/jfrog-security-advisories * Microsoft CVE-2026-62911 advisory: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62911 * NCSC-NL Exchange alert: https://www.ncsc.nl/alerts/ernstige-kwetsbaarheden-in-microsoft-exchange-server Call to Action * Subscribe: Stay updated on cybersecurity threats. * Leave a Review: Let us know what you think. * Join the Conversation: Follow our community and ask questions. Sponsor (if applicable) No sponsors this episode Podcast Socials & Website * Website: https://www.youvealreadybeenhacked.com * X: @professorcyberrisk * YouTube: https://www.youtube.com/@YABHPodcast * Discord/Community Forum: https://discord.gg/cz3xdsrqAE

0:00-31:08

transcript

No transcript — this publisher did not publish one.

show notes

Hosts

* Professor CyberRisk

* Cyber Cowboy Live


Cyber Maps

* Bitdefender Threat Map: https://threatmap.bitdefender.com/

* Checkpoint Threat Map: https://threatmap.checkpoint.com/

* Kaspersky Cyber Threat Map: https://cybermap.kaspersky.com/

* Talos Intelligence - ebc_spam Map: https://talosintelligence.com/ebc_spam


Episode Information

Title: Artifactory's Backdoor: Why Patching Isn't Enough

Episode Number: 3x61

Overview

Weekly roundup of the most critical cybersecurity developments from 2026-08-30 to 2026-09-03. Join Professor CyberRisk and Cyber Cowboy Live as they break down the stories that matter most.


Guest Information

None this episode


Topics Covered

* Software supply-chain poisoning via forged admin tokens (CVE-2026-82329)

* Mass-exposed Exchange servers and mailbox hijack (CVE-2026-62911)

* GDPR enforcement: French hospital fined €500,000 after 727,000-record breach

* Stealthit infostealer abusing Node.js Single Executable Applications


Top Stories

1. Hackers exploit critical JFrog Artifactory flaw to forge admin tokens - https://www.bleepingcomputer.com/news/security/hackers-exploit-critical-jfrog-artifactory-flaw-to-forge-admin-tokens/


Additional Cybersecurity News – Titles and URLs

2. Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks - https://www.bleepingcomputer.com/news/security/nearly-22-000-microsoft-exchange-servers-vulnerable-to-hijack-attacks/

3. French hospital fined €500,000 after breach exposes data of 727,000 - https://www.bleepingcomputer.com/news/security/french-hospital-fined-500-000-after-breach-exposes-data-of-727-000/

4. Stealthit infostealer gets a Node.js makeover — fake games and VPNs are the bait - https://hoploninfosec.com/stealit-malware-attacks


Resources & Links

* JFrog security advisories: https://docs.jfrog.com/releases/docs/jfrog-security-advisories

* Microsoft CVE-2026-62911 advisory: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62911

* NCSC-NL Exchange alert: https://www.ncsc.nl/alerts/ernstige-kwetsbaarheden-in-microsoft-exchange-server


Call to Action

* Subscribe: Stay updated on cybersecurity threats.

* Leave a Review: Let us know what you think.

* Join the Conversation: Follow our community and ask questions.


Sponsor (if applicable)

No sponsors this episode


Podcast Socials & Website

* Website: https://www.youvealreadybeenhacked.com

* X: @professorcyberrisk

* YouTube: https://www.youtube.com/@YABHPodcast

* Discord/Community Forum: https://discord.gg/cz3xdsrqAE