By industry

Manufacturing security news

All industries →

Sat, 12 Sept 2026

  1. CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security flaws impacting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild. Details of the vulnerabilities are as follows - CVE-2026-42016 (CVSS score: 8.1) - An incorrect authorization

    HighThe Hacker NewsJFrog

Fri, 11 Sept 2026

  1. More JFrog Artifactory bugs under attack, and all 3 have patches

    If you're waiting for a sign to upgrade to a fixed version: this is it

    The Register
  2. Artifactory flaws chained in attacks deploying backdoor malware

    Threat actors are exploiting critical and high-severity vulnerabilities in JFrog Artifactory to bypass authentication, gain administrative privileges, and deploy a Rust backdoor on vulnerable self-hosted servers.

    BleepingComputer
  3. EU's Cyber Resilience Act starts the 24-hour vulnerability clock

    Manufacturers must now disclose actively exploited flaws and severe security incidents through ENISA's new reporting platform

    The Register
  4. Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors

    Attackers have chained two flaws in JFrog Artifactory, the repository that software build pipelines pull from, to take administrator control of self-hosted servers and plant backdoors, cloud security company Wiz said in a report. Wiz saw the attacks between August 15 and September 8. JFrog had fixed both flaws before then, so only servers that had not been updated were open to them.

    The Hacker News
  5. Indonesia Hit by Android Banking App-Cloning Campaign

    The GoldFactory threat group exploits the Android Work Profile feature to deliver the Gigabud Trojan, while Mantax Otax spreads separately.

    Dark ReadingAndroid

Thu, 10 Sept 2026

  1. 2026-005: High Vulnerability in the Linux Kernel ("Copy Fail")

    On 29 April 2026, a high local privilege escalation vulnerability in the Linux kernel, tracked as CVE-2026-31431 and named "Copy Fail", was publicly disclosed. The vulnerability affects every mainstream Linux distributions shipping a kernel built since 2017. A public proof-of-concept exploit has been released. As of the date of this advisory, no distribution has shipped a fixed kernel package. The mainline fix was committed on 1 April 2026, but vendor updates are still pending across all major distributions. CERT-EU strongly recommends applying the interim mitigation immediately, prioritising Kubernetes nodes, and CI/CD runners exposed to untrusted workloads.

    CriticalUsed in attacksCERT-EULinux, Kubernetes

Tue, 8 Sept 2026

  1. OpenAI's Artifactory opened covert data-stealing channel alongside Hugging Face attack

    Researchers disclosed the cross-account trick the same day rogue agents exploited another zero-day for admin access

    The Register
  2. Microsoft security advisory – September 2026 monthly rollup (AV26-896) – Update 1

    Serial Number: AV26-896 Date: September 8, 2026 As of September 8, 2026, Microsoft is affected by vulnerabilities in the following products: .NET 10.0 installed on Linux .NET 10.0 installed on Mac OS .NET 10.0 installed on Windows .NET 11.0 installed on Linux .NET 11.0 installed on Mac OS .NET 11.0 installed on Windows .NET 8.0 installed on Linux .NET 8.0 installed on Mac OS .NET 8.0 installed on Windows .NET 9.0 installed on Linux .NET 9.0 installed on Mac OS .NET 9.0 installed on Windows ASP.NET Core 10.0 ASP.NET Core 11.0 ASP.NET Core 8.0 ASP.NET Core 9.0 Azure AI Language Authoring Azure Arc SQL Server Extension Azure Cosmos DB Azure CycleCloud Azure HDInsight HEIF Image Extension HEVC Video Extensions HEVC Video Extensions for Licensed Applications HEVC Video Extensions from Device Manufacturer Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 Microsoft .NET Framework 3.5 AND 4.7.2 Microsoft .NET Framework 3.5 AND 4.8 Microsoft .NET Framework 3.5 AND 4.8.1 Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 Microsoft .NET Framework 4.8 Microsoft .NET Framework 4.8.1 Microsoft 365 Apps for Enterprise Microsoft Access 2016 Microsoft Authentication Library (MSAL) Microsoft Authen

    Canadian Centre for Cyber SecurityMicrosoft, Windows, Linux

Latest manufacturing briefing

Manufacturing Cybersecurity Weekly Intelligence Brief — week ending 2026-09-14

12 stories affecting manufacturing tracked in the last seven days, 1 rated critical.

About manufacturing news

36
Stories
8
In the last 7 days
1
Critical in the last 7 days