
Attackers chain three JFrog Artifactory flaws to plant Rust backdoors inside Fortune 100 build pipelines
A 24-day exploitation campaign chained three CVEs — including a standalone CVSS 9.8 authentication bypass — to gain admin control of self-hosted Artifactory instances and deploy persistent Rust malware. Between 49–62% of public instances remain unpatched.










