CISA Advisories

Your AI Agent Might Be Working for Someone Else 🦠 + Patch JFrog Now 🚨

Two stories today share one uncomfortable theme: the tools you trust most are the ones attackers are aiming at. One turns your AI assistant into a delivery service for malware. The other is already being exploited inside the systems that build your software.

🦠 Your AI Assistant Just Got a Malicious New Skill

China's national cyber emergency response center is warning about "skill poisoning" — fake plugins, or "skills," uploaded to popular AI agent repositories that look exactly like legitimate tools. Researchers have already found eight of them impersonating real utilities. Once installed, they quietly hand attackers access to your files and remote control of the machine.

Here's what makes this different from the phishing you're used to: nobody has to click a sketchy link. The AI agent does the dangerous thing all on its own, because downloading and running tools is literally its job. If your team is installing agent plugins the way you'd install a browser extension — quickly, without checking who made it — that's now a doorway into your business.

Read more →

🚨 Attackers Are Already Inside JFrog Artifactory — And Most Instances Are Exposed

Three vulnerabilities in JFrog Artifactory are under active attack right now. Artifactory is the warehouse where companies store the building blocks of their software, so a break-in there isn't a normal breach — it's a chance to tamper with everything that gets built afterward. Attackers are creating admin accounts, planting backdoors and web shells, minting access tokens, and stealing keys.

The scary part is how many doors are still open. Security firm Wiz found roughly 59% and 62% of instances exposed to two of the three flaws. Patches exist for all three. If your organization runs Artifactory, today is the day to patch it, lock down network access, and audit every recent admin login for anything you don't recognize.

Read more →

Stay ahead of threats with GOCO Security at gocosecurity.com.

Comments

Popular Posts