The Desk · The Wire · Hacked Today? · Data Center RSS
The Perimeter Site

Your Management Tools Are Just Delivery Drivers

The Perimeter Desk
2026-09-14
# Your Management Tools Are Just Delivery Drivers Maybe it's Monday night and you're still burnt out from working the weekend. Or you're staring at a dashboard that says everything is fine, but your gut tells you otherwise. I've done this long enough to know which one is lying. Everyone will be obsessed with the JFrog Artifactory mess tomorrow. But why not talk about the ConnectWise ScreenConnect situation first? It's more honest. We've got a vulnerability, CVE-2026-84869, and attackers are using it to spread like a worm through VBScript payloads. Read that again. VBScript. It's 2026. We're still fighting the same ghosts I saw during Code Red back in 2001, and the mechanics have changed, sure, but that hunger for fast and mindless spread is exactly the same. When a tool built to give you remote administrative access turns into a worm vector, you aren't just looking at a few servers, and your blast radius hits every single endpoint that agent touches. If I get paged for this, I don't care about the attacker or what country they call home. Who cares? I want to know how many instances are unpatched and where our immutable backups are sitting. What would this cost you on a Tuesday? A total loss of trust in your primary management plane. That’s a bad day. Then we have JFrog. Three high-severity flaws being exploited to bypass authentication and drop backdoors. Now, some CISO is going to put out a statement calling this "sophisticated." I hate that word. The industry loves the word "sophisticated. It's a blanket they throw over things like disaster architecture or a known flaw they just didn't patch. There's nothing sophisticated about using an authentication bypass to grab admin privileges. It is just basic hygiene failing on a large scale. The exploit isn't the real headache, though. It is the second-order effect. Companies use JFrog Artifactory as their well for dependencies (and if you poison the well, every piece of software built with those artifacts becomes a Trojan horse). You aren't dealing with one bad server, and you're looking at a supply chain infection that might take months to fully purge from your environment. It makes me think of NotPetya. That started with some accounting software, but the real disaster was how it used trusted pathways to burn through global networks in hours, and this JFrog mess has the same DNA. It uses infrastructure trust to jump right over the perimeter. Then you have CISA screaming about a max-severity flaw in GitLab being exploited in the wild. It fits the pattern. Technology is the most targeted sector right now (ranking #1 of 12 this week). There are just over 300 stories, or 311 to be exact. Today alone added another 64 incidents to that pile. Why do we keep doing this? The thread here is a systemic failure in how we handle "trusted" tools, and we treat artifact repositories, remote support agents and CI/CD pipelines as safe zones. They aren't. They are the highest-value targets because they offer the shortest path to the crown jewels. Some of you might argue you can't patch every tool in a modern stack the second a CVE drops. You're right. You can't. That is why you segment management traffic and act as if your build servers are already compromised. If your ScreenConnect server can talk to your entire production environment without any friction, you didn't build a network. You built a highway for attackers. I looked at the wire from this week and saw 378 data breaches. That number is absurd. It tells me that while we all argue about zero-days and AI agents, the basics are falling apart. We have a massive amount of noise (63 stories on AI security today alone) distracting us from the fact that basic authentication bypasses are still how people get ruined. The question you should be asking your team tonight isn't "Are we patched against CVE-2026-84869?" Here's the thing. If our management tool decided to push a malicious payload to every single server in the fleet this second, how long before we actually noticed? And then there is the other part (the scary part), which is whether we can kill that connection without accidentally locking ourselves out of the house. If you don't have a concrete answer, don't bother calling it sophisticated when it happens. Just call it what it is: a choice.
◼

Sources

The reporting this analysis was built from. Follow the originals before acting on anything here.

  1. Three JFrog Artifactory Flaws Exploited for Backdoor Deployment SecurityWeek
  2. CISA: Hackers now exploit max severity GitLab flaw in attacks BleepingComputer
  3. Malicious actors already using critical GitLab flaw, CISA and others warn - Cybersecurity Dive Google News Security
  4. ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks SecurityWeek
  5. Revolut Data Breach Exposes Passport Copies, KYC Selfies and Full Transaction Histories - cyberpress.org Google News Security
  6. Weekly Cybersecurity Newsletter Bulletin – Microsoft 0-day, FortiOS, PAN-OS Flaw, Revolut Data Breach, and... - CyberSecurityNews Google News Security
  7. Revolut hit by extortion as hackers leak client dossiers on Telegram - Pasquale Pillitteri Google News Security
  8. Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution SecurityWeek

How stories are selected and rated

← More from the Desk Live Wire →

About · Methodology · Contact · Privacy

Tracking a CVE from this story? Hazard shows which vulnerabilities are confirmed exploited in the wild — and what the resulting breaches have cost UK organisations.

DISCLAIMER: Articles on this site are generated automatically from public security news feeds for educational and informational purposes. They may contain errors, and nothing here constitutes security, legal, or compliance advice. Verify details against original advisories and vendor bulletins before acting on them.