Daily Digest

AI API Key Hijacking, Critical Exploits, and EU Reporting Mandate

September 1, 2026
8 articles (5 new, 3 updated)
24 min read

Summary

Critical Vulnerabilities Under Active Exploitation:

  • CVE-2026-82329 (JFrog Artifactory Auth Bypass): A critical authentication bypass vulnerability in self-hosted JFrog Artifactory instances is being actively exploited, allowing unauthenticated attackers to gain administrative privileges. Patches were released on August 28, 2026, and immediate updates are recommended.
  • CVE-2026-0768 (Langflow AI RCE): A critical remote code execution vulnerability (CVSS 9.8) in the Langflow AI low-code platform is under active exploitation. Unauthenticated attackers can execute arbitrary code with root privileges, leading to reconnaissance and credential theft. Attacks have been observed originating from Russia.
  • CVE-2026-78319 (SAUTER Building Controllers RCE): A critical remote code execution vulnerability (CVSS 9.8) affects SAUTER building automation controllers due to a TOCTOU race condition. This flaw could allow unauthenticated attackers to gain full control of devices managing essential building systems. Patches are available.

Threat Landscape Updates and Emerging Risks:

  • [UPDATE] Attackers Hijack AI API Keys: AI safety non-profit METR disclosed two security incidents demonstrating 'token jacking' threats. A March 2026 incident resulted in approximately $600,000 in fraudulent AI credit consumption, and a May 2026 campaign involved automated probing and credential stuffing. These incidents highlight the need for robust AI resource security.
  • [UPDATE] AI Scripts Target Siemens PLCs: Forescout's Vedere Labs demonstrated AI's ability to accelerate exploit development against industrial control systems, porting an RCE exploit between PLC models in under 8 hours. This research supports warnings about AI-driven threats to critical infrastructure, indicating increased attack speed and a lower barrier to entry for sophisticated OT exploits.
  • [UPDATE] McKesson Breach and Ransom Demand: The ShinyHunters group has issued a $55 million ransom demand to McKesson following a data breach. The attack targeted both Snowflake and Salesforce instances, impacting customer data across multiple business units and confirming a double-extortion tactic.
  • Phishing Campaign Targets 9,000+ Orgs: A large-scale phishing campaign has targeted over 9,000 organizations with debt-relief-themed emails. The campaign uses social engineering to lure victims into vishing calls, aiming to steal financial and personal information.

Policy and Industry Notes:

  • EU Cyber Resilience Act Reporting Mandate: Manufacturers of connected products sold in the EU must comply with the Cyber Resilience Act's (CRA) new reporting obligations starting September 11, 2026. The rules mandate reporting actively exploited vulnerabilities and severe incidents to ENISA within 24 hours.

Filter by Category

New Articles (5)

Updated Articles (3)

📢 Share This Publication

Help others stay informed about cybersecurity threats

📅 Daily Edition

Curated and deduplicated every day from dozens of trusted sources — giving you one clean, consolidated view of what matters in cybersecurity.

🔢 Deduplication Applied

Related stories are merged into a single evolving article rather than repeated as separate entries — cutting through noise so you only read what's new.

🔗 Full Articles Linked

Every entry links to its full enriched article — complete with MITRE ATT&CK mappings, extracted IOCs, and actionable detection and mitigation guidance.