This report covers August 31–September 6, 2026.
Executive summary
- Active exploitation affected PaperCut and SonicWall infrastructure, while observed attacks against Artifactory demonstrated how quickly privileged enterprise platforms can become credential and supply-chain risks.
- Compromises involving Coder, Langflow, and METR exposed the concentration of cloud, development, and model-provider credentials around modern engineering and AI services.
- G7 agencies called for immediate post-quantum preparation, while new joint guidance addressed communications during disruptive IT and OT incidents.
- AI-assisted PLC exploit research weakened assumptions that obscure embedded architectures provide durable protection, but it did not demonstrate autonomous or active attacks.
Active exploitation and trusted administrative paths
PaperCut and SonicWall flaws require validation beyond patch status
Attackers were reported using chained PaperCut authentication-bypass and remote-code-execution flaws in data-theft intrusions, and CISA added both vulnerabilities to its Known Exploited Vulnerabilities catalog on August 31 (BleepingComputer). PaperCut’s vulnerability log identifies the affected NG and MF platform releases and available fixes (PaperCut). The number and sectors of compromised organizations remain unknown.
Separately, SonicWall confirmed active exploitation of two SMA 1000 vulnerabilities and directed customers to install fixed firmware (SonicWall). Canada’s Cyber Centre corroborated the exploitation and KEV status (Cyber Centre); public reporting indicated that no substitute workaround was available (CSO Online).
These systems sit on trusted administrative or remote-access paths. CISOs should require evidence that every deployment is updated, determine whether vulnerable interfaces were exposed, preserve appliance and application telemetry, and hunt for activity predating remediation. Credentials or tokens that traversed a potentially compromised gateway should be assessed for rotation rather than assumed safe after patching.
Artifactory exploitation threatens the software delivery trust chain
JFrog disclosed that CVE-2026-82329 affected specified self-hosted Artifactory versions under a default configuration; its cloud service was not listed as affected (JFrog). Honeypot-based reporting subsequently observed attempts beginning September 1 to create administrator tokens and enumerate users, credentials, groups, and federated relationships (BleepingComputer, CSO Online). This establishes hostile weaponization, but not the number of successful victim compromises.
Administrative access to an artifact repository can create downstream exposure involving source code, secrets, build systems, and software integrity. Organizations should upgrade every self-hosted branch, restrict reachability, revoke potentially exposed administrative and federated credentials, and review audit records, artifact integrity, and release activity—not simply close the vulnerability ticket.
Coder’s trusted registry delivered malicious infrastructure modules
Coder disclosed that an attacker compromised a Cloudflare API key on August 31 and redirected some registry.coder.com traffic to unauthorized infrastructure. Tampered Terraform modules searched for and exfiltrated AWS, Azure, GCP, and other credentials; Coder said it contained the redirection the same day (Coder). The company had not quantified affected customers or confirmed successful credential theft by the end of the window.
This was compromise of trusted distribution infrastructure, not a lookalike package repository. Organizations using Coder should determine whether workspaces fetched modules during the disclosed interval, rotate credentials accessible to potentially affected environments, review module provenance, and inspect outbound connections and infrastructure changes. Procurement and engineering leaders should also verify whether existing controls can rapidly distrust a previously approved package source.
ScreenConnect activity shows propagation through legitimate remote-management functions
Huntress observed rogue ScreenConnect clients across unrelated organizations transferring and executing a multistage VBScript payload when endpoints connected. ConnectWise acknowledged a file-transfer issue on September 3 and recommended disabling the relevant permission while it prepared a formal fix (Huntress). A CVE and final vendor resolution were not available during the reporting window, and the initial rogue-client installation involved social engineering.
Remote-management platforms have privileged reach, including into industrial support environments. Teams should disable nonessential file transfer, inventory authorized and unauthorized clients, review session logs, and hunt for unusual wscript.exe child processes and the indicators supplied by Huntress. Confirmed compromised systems should be handled as incidents rather than remediated by removing the client alone.
AI infrastructure and credential concentration
Langflow attacks targeted cloud, model, and administrative secrets
CVE-2026-0768 is an unauthenticated Langflow code-injection vulnerability capable of remote code execution (GitHub Advisory Database). In-window honeypot reporting described hundreds of exploit attempts that searched environment variables and files for OpenAI API keys, AWS credentials, Langflow secrets, SSH information, and shell history (BleepingComputer, SecurityWeek). The telemetry does not establish how many real systems were successfully compromised.
The practical issue is architectural: low-code AI services often inherit access to valuable cloud and production credentials. Treat Langflow and similar orchestration platforms as privileged application runtimes. Find exposed instances, update them, restrict network paths, rotate accessible secrets, and hunt for environment-variable and filesystem discovery.
METR disclosure illustrates fail-open AI application risk
METR disclosed that a fail-open authentication weakness in a publicly deployed AI-assisted application exposed a model-provider API key. An attacker added an SSH key and consumed approximately $600,000 in credits over three weeks; METR also described a separate query-scoping flaw that made unpublished evaluation data technically reachable, although it found no evidence attackers accessed that data (METR).
The lesson extends beyond research organizations. Externally deployed AI applications need mandatory security review, fail-closed authentication, spending limits, independent identities, and separation from confidential model or evaluation environments. Sensitive credentials should not be placed on unmanaged experimental infrastructure merely because an application is considered temporary.
OT security and resilience
AI-assisted PLC exploit porting reduced effort—but still needed experts
Forescout researchers reportedly used Anthropic’s Claude to adapt a pre-authentication exploit from one WAGO PLC model to another and execute ARM shellcode on physical hardware. The experiment took more than eight hours, cost about $535 in API usage, and required extensive expert steering; a later attempt to generate a command-and-control implant bricked the test device (SecurityWeek, Cloud Security Alliance). There is no evidence from this work that adversaries are currently applying the method to industrial targets.
The result nevertheless weakens risk acceptances based on exploit-development difficulty or architecture obscurity. OT leaders should prioritize consequence-based controls: restrict management protocols, validate segmentation and engineering-workstation protections, and reassess unsupported devices where patching is unavailable. Model-generated payload unreliability also reinforces the need for safe testing environments and recovery plans.
Data concentration and third-party risk
C-Track breach exposed sensitive court records across jurisdictions
West Publishing and Thomson Reuters disclosed that an unauthorized party obtained files from the C-Track court-management cloud environment in March 2026. The environment served courts across multiple U.S. and Canadian jurisdictions, and potentially affected files included confidential, sealed, or redacted records and personal information such as Social Security, driver’s-license, health, and medical data (South Carolina Judicial Branch). The affected population, file volume, attacker, and initial access method were not publicly established during the window.
The breach illustrates concentration risk when one provider holds restricted records for otherwise independent organizations. Third-party risk owners should verify notification deadlines, tenant-level logging, backup protection, data-retention terms, and controls for sealed or specially restricted information. Legal and privacy specialists should assess obligations by jurisdiction rather than treating the incident as a uniform exposure.
Governance and preparedness
G7 agencies move post-quantum migration into current planning
The G7 Cybersecurity Working Group called on public- and private-sector organizations to begin post-quantum preparation now, emphasizing cryptographic inventories, prioritized migration, crypto agility, procurement requirements, long transition periods, and “harvest now, decrypt later” exposure (ANSSI). The statement is strategic guidance, not a binding regulatory deadline.
Boards and executives do not need to select replacement algorithms themselves, but they should fund an inventory and ownership model. Priorities should reflect how long information must remain confidential, the lifespan of deployed systems, and normal refresh cycles. Long-lived industrial, identity, safety, and intellectual-property systems deserve early attention, while procurement should begin requiring crypto agility where products can reasonably support it.
Joint guidance addresses communications during IT and OT outages
CISA, the FBI, and international partners published guidance for service providers communicating during cyber-related IT and OT outages. It covers transparency, audience-specific messaging, operational security, legal requirements, cascading dependencies, containment, and disruption caused by defensive isolation (CISA). The guidance does not replace sector-specific reporting or disclosure obligations.
Organizations should exercise communications alongside technical response, preapprove decision rights and message templates, and account for deliberate OT isolation in continuity planning. This supports the NIST CSF 2.0 Respond and Recover outcomes: communications should be timely and governed without disclosing details that undermine containment.
Also on the radar
- The U.S. Justice Department announced a multinational disruption of the long-running Sality peer-to-peer botnet; organizations receiving sinkhole or partner notifications should investigate residual infections on legacy or unmanaged endpoints (DOJ).
- An actively exploited Chrome V8 type-confusion vulnerability requires accelerated updates across Chrome and other affected Chromium-derived browsers, although campaign scope remained undisclosed (CERT Vanuatu).
- CISA’s September 3 release included ten ICS advisories, including one concerning the NetStaX EtherNet/IP stack; industrial operators should ask suppliers whether affected components are embedded in their products (CISA).
My Perspective
The week’s common thread is not simply patch volume; it is the concentration of trust in remote-access gateways, artifact repositories, package registries, AI runtimes, and cloud service providers. Compromise of one control plane can expose credentials or create downstream effects well beyond the original system. This continues the control-boundary concerns highlighted in last week’s report. Leaders should prioritize verified inventories, independent identities, constrained trust relationships, and telemetry that can answer whether exploitation occurred before remediation. Those measures are more valuable than treating each advisory as an isolated vulnerability-management task.
What to watch next week
- Vendor updates on the ScreenConnect file-transfer issue, including a formal fix, affected versions, and any CVE assignment.
- Evidence clarifying the victim scope and downstream credential use associated with the Coder, Artifactory, PaperCut, and SonicWall activity.
- Product-specific post-quantum roadmaps and procurement guidance that translate the G7 statement into practical migration dependencies.
