Attackers exploit security flaws in JFrog Artifactory to compromise vulnerable self-hosted servers, obtain administrative access, and deploy backdoor malware. Multiple reports describe threat activity that chains the weaknesses to bypass authentication and elevate privileges, then installs a malicious payload. Bleeping Computer reports that the deployed backdoor is written in Rust.
Wiz, cited by The Hacker News, reports that the activity occurs by chaining two flaws affecting Artifactory instances used as repositories for software build pipelines. The firm says it observed attacks between August 15 and September 8. The Hacker News also notes that JFrog fixes both issues before that window, meaning exploitation is primarily relevant to installations that were not updated in time.
Across the outlets, the core description aligns: chained Artifactory vulnerabilities lead to admin-level control and the planting of a backdoor on self-hosted systems. Differences mainly relate to emphasis and technical detail, such as the malware implementation details highlighted by Bleeping Computer versus the timing and vulnerability-chaining narrative emphasized by The Hacker News.