Threat actors are exploiting critical and high-severity vulnerabilities in JFrog Artifactory, BleepingComputer reports. The attacks chain the flaws to bypass authentication, gain administrative privileges and deploy a Rust backdoor.

The attacks target self-hosted Artifactory servers, where the chain starts with authentication bypass and ends with administrative privileges and a Rust backdoor. The report does not list affected versions or a patch, so the exposed group is organisations running those servers themselves.