Back to Archive
THREAT INTELLIGENCE BRIEFยทSaturday, September 12, 2026ยทAI-Powered

The most urgent threat this week is the active, in-the-wild exploitation of a maximum-severity (CVSS 10.

The most urgent threat this week is the active, in-the-wild exploitation of a maximum-severity (CVSS 10.0) path traversal vulnerability in GitLab (CVE-2026-85706). This vulnerability is listed on the CISA KEV list, indicating confirmed exploitation, and public proof-of-concept exploit code is available, making it a critical priority for immediate patching. Additionally, critical remote code execution vulnerabilities in Check Point VPNs require attention. Other significant threats include the chaining of flaws in JFrog Artifactory to deploy backdoors, a major data breach at the Florida DMV, and the novel use of AI agents to automate exploitation at scale against PaperCut servers.

46 articles analysed3 CVEs mentioned

Threat Categories

๐Ÿ›Vulnerabilities3
๐Ÿ’€Malware1
๐Ÿ“„Data Breach1

Article Analyses (5)

GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure

high
CVE-2026-85706
KEVPoC

Details

A critical path traversal vulnerability in the repository commits API allows an unauthenticated attacker to read arbitrary files from a targeted GitLab server. The flaw is being actively probed and exploited in the wild, beginning just one day after public disclosure.

Affected Systems

GitLab Community Edition (CE) and Enterprise Edition (EE).

Potential Impact

An attacker can exfiltrate sensitive data, including configuration files, credentials, and source code, leading to a full system compromise.

Mitigations

Immediately patch all GitLab servers. This vulnerability is on the CISA KEV list with a required remediation date of 2026-09-14.

The Hacker NewsDraft Post

Check Point Patches Critical VPN Vulnerabilities

critical
CVE-2026-85102CVE-2026-85103
EPSS 0.4%

Details

Two critical vulnerabilities, CVE-2026-85102 and CVE-2026-85103, have been discovered in Check Point VPN products. These flaws can be exploited for remote code execution (RCE), potentially allowing an attacker to take full control of the affected VPN gateway.

Affected Systems

Check Point VPN products (specific versions not detailed in articles).

Potential Impact

Compromise of a VPN gateway could lead to unauthorized network access, data interception, and lateral movement into the corporate network.

Mitigations

Apply the patches released by Check Point immediately. Prioritize patching on all internet-facing VPN gateways.

SecurityWeekDraft Post

Artifactory flaws chained in attacks deploying backdoor malware

critical

Details

Threat actors are chaining multiple critical and high-severity vulnerabilities in JFrog Artifactory. The attack chain allows for bypassing authentication, escalating privileges to an administrator level, and deploying a persistent Rust-based backdoor on the server.

Affected Systems

Unpatched, self-hosted JFrog Artifactory servers.

Potential Impact

Compromise of the Artifactory server can poison the software supply chain, leading to widespread distribution of malware in downstream applications and development environments.

Mitigations

Ensure all self-hosted JFrog Artifactory instances are updated to the latest patched versions. Scan for indicators of compromise related to the Rust backdoor.

BleepingComputerDraft Post

Florida confirms DMV database breached via stolen police account

critical

Details

The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) confirmed a data breach of its DAVID driver database. Attackers gained access using the stolen credentials of a police department employee, bypassing security controls.

Affected Systems

Florida's Driver and Vehicle Information Database (DAVID).

Potential Impact

Exposure of sensitive personal information of Florida residents, potentially leading to identity theft and fraud. The breach highlights the risk of compromised credentials from trusted third parties.

Mitigations

Review and enforce multi-factor authentication for all privileged accounts. Audit access logs from third-party partners and law enforcement agencies for anomalous activity.

BleepingComputerDraft Post

AI agents exploited PaperCut flaws to breach 395 organizations

high

Details

A threat actor developed an exploit for vulnerabilities in PaperCut print management software and then used AI agents to automate the exploitation process at scale. This novel technique resulted in the compromise of at least 440 PaperCut instances across 395 organizations in 48 countries.

Affected Systems

Vulnerable instances of PaperCut NG/MF print management software.

Potential Impact

The use of AI agents to automate exploitation demonstrates a significant increase in the speed and scale of attacks, enabling a single actor to compromise hundreds of organizations with minimal manual effort. This represents an emerging threat vector.

Mitigations

Ensure all PaperCut servers are patched. Monitor for unusual activity from print management servers. Evaluate security controls' effectiveness against automated, high-velocity attacks.

Help Net SecurityDraft Post
Generated by gemini-2.5-pro