Here is your briefing for Friday, September 11, 2026. Wiz says attackers chained two JFrog Artifactory bugs between August fifteenth and September eighth to take administrator control of self-hosted build repositories and plant backdoors. C.V.E. twenty twenty-six dash forty-two thousand eighteen hands out an internal anonymous-user token even when anonymous access is off. C.V.E. twenty twenty-six dash forty-two thousand sixteen then swaps that low-privilege token for administrator scope, because Artifactory checked the signature and issuer but not what the token was allowed to do. In some cases the path from first request to a new admin account took under five minutes, and the noisy actions still logged as token colon anonymous. Attackers left admin accounts behind, installed malicious Groovy plugins for code execution, and dropped a custom Rust backdoor. A third flaw, C.V.E. twenty twenty-six dash eighty-two thousand three hundred twenty-nine, is a nine point eight auth bypass on its own, and Fastly counted about four hundred six thousand exploitation attempts in a single day. Patch your branch, rotate the join key, revoke tokens, and hunt for surprise admin accounts. A patch does not undo what they already minted. Cisco says three distinct clusters are exploiting Secure Firewall Management Center flaws that CISA already put on a September twelfth federal patch clock. The perfect-ten auth bypass, C.V.E. twenty twenty-six dash twenty thousand seventy-nine, and a lower-privilege login bug, C.V.E. twenty twenty-six dash twenty thousand three hundred sixteen, are no longer just K.E.V. checklist items. One cluster drops J.S.P. webshells and pulls credentials from internal databases. Another deploys Netcat, config harvesters, and a Cyclops Blink variant tied to Russia's Sandworm. A third, U.A.T. dash eleven thousand nine hundred eighty-eight, lives off the land inside F.M.C., tunnels out, builds an encryption target list, kills security tools, and deploys Qilin ransomware. Your firewall brain is now ransomware staging. Hotfix F.M.C. before tomorrow's deadline, then assume anything managed through it may already be mapped. Gen Digital says China-linked U.N.C. three thousand five hundred sixty-nine exploited a flaw in Sogou Input Method, the Windows Chinese typing stack used by hundreds of millions, to land the GRAYRABBIT backdoor. A crafted sgbiz colon link handed arguments to Sogou's helper with no filtering, opened the skin store in a bundled Chromium eighty browser with the sandbox off, and ran a twenty twenty-one V-eight bug Google fixed years ago. Tencent pushed a twelve-day fix in April as C.V.E. twenty twenty-six dash fifty-one thousand nine hundred ninety, but Gen says the ancient Chromium build and disabled sandbox were left in place. The loader hid in a seven-Zip side-load, checked for a real desktop before decrypting, and wiped itself into an N.T.F.S. alternate data stream. Update Sogou, watch plain T.C.P. on four forty-three to mail.uaiubifas.top, and remember popular desktop utilities can still ship a nineteen-eighties threat model with a twenty twenty-six install base. Okta dug through a seven-gigabyte infostealer dump from August and found thousands of unexpired session tokens and A.P.I. keys for Google, Anthropic, OpenAI, Microsoft, Cursor, and more. Of nearly forty-five thousand J.W.T.s, five hundred fifty-five looked like A.I. service auth, and one thousand eight hundred forty-three tokens were still live on release day. Replay the token and you are logged in without a password or M.F.A. challenge. Underground shops already sell Claude, Cursor, ChatGPT, and Gemini access with twenty-four-seven support, and Google says buyer demand for premium model accounts and coding I.D.E.s is rising. This is L.L.M.jacking next to classic cloud cryptomining: steal the session, burn the victim's bill, skip the login screen. Short-lived tokens, device-bound sessions, scoped keys, and monitoring for replay beat another checkbox on the password form. Ars reports Google won an auction for a huge Spirit Airlines operational dataset in bankruptcy, and vendors are panicking that the vague sale language may sweep in third-party I.P. Springshot, whose ops platform ran Spirit to the last flight, says tens of thousands of emails and workflow artifacts may be theirs, not Spirit's, and that Google could use that data to build a rival airline A.I. stack. Unions and pilots warn eighty thousand email accounts, one hundred million emails, and five hundred million Teams messages were never consented for A.I. training, and that flight-safety reporting depends on pilots trusting confidentiality. A September sixteenth hearing will test whether bankruptcy is the new land grab for model fuel. Possession of data is not ownership, and once it is inside a frontier model, scrubbing it back out is a fantasy. Build-pipeline admin chains, firewall managers turned into Qilin launchpads, a national input method still shipping Chromium eighty, stealer logs minting A.I. skeleton keys, and a bankrupt airline's ops data headed to Google. The control planes keep moving upstream, into the tools that build, manage, type, authenticate, and train. That's the briefing. Stay sharp, keep your systems patched, and we'll see you tomorrow. Kindle: https://www.amazon.com/dp/B0HHMH88H9 Apple Books: https://books.apple.com/us/book/local-ai-on-the-mac/id6807243472 https://mattchapman.net Support the show