JFrog Artifactory flaw lands in the KEV catalogue
September 1, 2026. From issue 4 of The Compliance Brief, 2 stories for teams that commission penetration tests.
Issue 4 of The Compliance Brief was published on September 1, 2026. 2 of its 5 stories bear on exploited vulnerabilities and security testing, and they are below in short form. The full issue, with every take in full, is on traztech.ca.
Free weekly email
Get the next issue on Tuesday
One email a week: what changed in security and compliance, and what it means for teams that commission penetration tests.
Free. One email every Tuesday from Jacob Masse, and nothing else: signing up here does not add you to any other sequence. One click unsubscribes.
Source: CISA
CISA added three actively exploited vulnerabilities to the Known Exploited Vulnerabilities catalogue: an ownCloud authentication flaw, an unspecified Linux kernel issue, and a path traversal issue in JFrog Artifactory. The catalogue is tied to CISA's binding directive on prioritizing security updates by risk for federal agencies.
Our take, in short
Artifactory is the interesting one for this audience because it usually sits inside the build environment with credentials to everything downstream. You are not a US federal agency, but plenty of your customers now write KEV remediation timelines into their vendor contracts, and auditors have started asking how you learn a KEV entry exists at all.
Read the full take on traztech.ca
CISA red-teamed two organizations and only one saw it coming
Source: CISA
CISA ran simultaneous red team assessments at two organizations and published the comparison. In both cases the red team reached full domain compromise and touched sensitive business systems and cloud resources.
Our take, in short
Both were breached, so the difference was entirely in response, and that is the same argument I make when a founder asks why we care so much about their logging and alerting before a SOC 2 audit. Your auditor will accept a screenshot of an alerting policy, your enterprise buyer's security team increasingly will not, and this advisory is a...
Read the full take on traztech.ca
Related on GetPentest
- Retest and remediation verification
- Finding severity triage
- How to write a penetration test scope
- ISO 27001 penetration testing
Also in issue 4
Outside exploited vulnerabilities and security testing, but in the same email:
- McKesson breach came through third-party applications
- Two arrests in the TeamPCP open-source supply chain spree
- Cyber claims are fewer and far more expensive
Older: issue 3 All issues on GetPentest Newer: issue 6
Free weekly email
Get it every Tuesday
The next issue goes out Tuesday morning. Read it in your inbox instead of finding it here a week later.
Free. One email every Tuesday from Jacob Masse, and nothing else: signing up here does not add you to any other sequence. One click unsubscribes.