AUTO-UPDATED

CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners

The U.S. Cybersecurity and Infrastructure Security Agency has added seven critical vulnerabilities to its Known Exploited Vulnerabilities catalog, mandating urgent security patches for federal agencies by September.

Key Points

  • CISA added seven flaws affecting SonicWall, Sangoma Switchvox, JFrog Artifactory, Kludex Starlette, Kestra OSS, and Berri LiteLLM to its KEV catalog.
  • Vulnerabilities include critical remote code execution risks, with two flaws in SonicWall and Kestra receiving maximum CVSS scores of 10.0.
  • Threat actors are actively weaponizing these exploits to deploy reverse shells, cryptocurrency miners, and harvest sensitive API keys and database credentials.
  • Microsoft and Wiz reports indicate that AI infrastructure, including LiteLLM and RAGFlow, has become a primary target for persistent unauthorized access and data theft.
  • Federal Civilian Executive Branch agencies must patch most listed vulnerabilities by September 5, 2026, with the remaining two due by September 16, 2026.

Why it Matters

These active exploits highlight a growing trend of attackers targeting AI-native infrastructure and workflow automation tools to steal high-value credentials and provider keys. Organizations must prioritize these updates to prevent long-term persistence, resource hijacking, and the compromise of sensitive backend data tiers.
Internet Published by info@thehackernews.com (The Hacker News)
Read original