This website uses cookies

Read our Privacy policy and Terms of use for more information.

Summary: Cisco revealed that three distinct threat clusters linked to ransomware and state-sponsored activity have been exploiting two recently patched Secure Firewall Management Center (FMC) vulnerabilities. The primary flaw is CVE-2026-20079 (CVSS 10.0), an authentication bypass in the FMC web interface that allows an unauthenticated remote attacker to execute scripts and obtain root access. The second is CVE-2026-20316 (CVSS 5.3), which permits unauthenticated login with a low-privilege account and can be chained for further access.

Cisco Talos identified clusters UAT-12197 (web shells and credential harvesting), UAT-11823 (Netcat reverse shells, config harvesting, and a Cyclops Blink variant), and UAT-11988 (Qilin ransomware deployment via living-off-the-land techniques after initial access). CISA has added CVE-2026-20079 to its KEV catalog with a September 12 remediation deadline for federal agencies.

Key takeaway / Actionable note: Apply the available Cisco hotfixes for both CVEs immediately and treat any internet-exposed FMC as potentially compromised pending full review of authentication logs and managed-device configurations.

Summary: PaperCut released regular maintenance releases (NG/MF 26.0.5, 25.0.13, and 24.1.10) that fully replace earlier emergency patches for two actively exploited vulnerabilities, CVE-2026-81578 and CVE-2026-82078. The new releases include all prior security fixes plus additional hardening and have completed full QA testing.

These flaws have been under active exploitation; a related campaign used AI agents to scale attacks against hundreds of instances.

Key takeaway / Actionable note: Deploy the new maintenance releases across all PaperCut NG/MF environments and verify that emergency patches have been superseded.

Summary: A likely Russian-speaking threat actor used hundreds of AI agents (leveraging OpenAI Codex and DeepSeek models plus commodity tools) to develop, test, and deploy exploits for the PaperCut flaws CVE-2026-81578 and CVE-2026-82078. GreyNoise observed the campaign begin around August 31 and compromise at least 440 PaperCut instances belonging to 395 organizations across 48 countries.

Attackers harvested credentials from 280 victims, OS/domain secrets from 147, and domain-admin privileges at 12 organizations, with education the most heavily hit sector. Paths included LSASS dumping, pass-the-hash, noPac, and DCSync. Time-to-compromise was extremely short in observed cases.

Key takeaway / Actionable note: Prioritize PaperCut patching and hunt for post-exploitation artifacts (new domain accounts, Ligolo-ng, Mimikatz, BloodHound activity) on any previously vulnerable servers.

Summary: Wiz reported that attackers chained two previously patched JFrog Artifactory flaws—CVE-2026-42018 (unauthenticated internal anonymous token issuance) and CVE-2026-42016 (token scope elevation)—to obtain administrator control on self-hosted servers and plant backdoors between mid-August and early September. A third critical auth-bypass, CVE-2026-82329, was also exploited independently.

Attackers created persistent admin accounts (often with POC-style names), installed malicious Groovy plugins, and deployed droppers or a custom Rust backdoor. Compromises occurred only on unpatched instances; cloud Artifactory was not affected.

Key takeaway / Actionable note: Upgrade self-hosted Artifactory to the fixed builds listed in JFrog’s security advisories for your branch, rotate join keys and tokens, and audit for unexpected administrator accounts and plugins.

Summary: Gen Digital research detailed how China-linked group UNC3569 (tracked by Google Threat Intelligence) exploited a flaw in the widely used Sogou Input Method to deliver the GRAYRABBIT backdoor. The attack chain began with a crafted link and ended with full control under the logged-in user’s privileges.

Tencent (Sogou’s owner) had fixed the vulnerability in April 2026. The group has historically targeted government, education, technology, and finance sectors primarily in East and Southeast Asia.

Key takeaway / Actionable note: Ensure Sogou Input Method is fully updated on Windows endpoints in relevant regions and monitor for GRAYRABBIT indicators.

Summary: Identity-verification firm IDScan confirmed that an unauthorized third party may have accessed and/or copied customer information from its cloud platform, following reports of a dark-web service offering more than 153 million U.S. and Canadian driver’s-license scans (plus millions of other ID documents).

The company stated the exposed data may include full names and driver’s-license or other government-issued identification numbers. The FBI’s New Orleans field office is investigating; IDScan is providing free credit monitoring to potentially affected individuals.

Key takeaway / Actionable note: Organizations that use IDScan for identity checks should review retention practices and monitor for downstream identity-fraud activity involving scanned documents.

Summary: GitLab urged immediate patching of a maximum-severity path-traversal vulnerability tracked as CVE-2026-85706 affecting its servers. The company recommended applying the fix without delay to prevent potential unauthorized access or further compromise.

Key takeaway / Actionable note: Apply the GitLab security update for CVE-2026-85706 on all self-managed instances as soon as possible.

Summary: Check Point disclosed and patched two critical (CVSS 9.8) vulnerabilities in VPN certificate handling—CVE-2026-85102 and CVE-2026-85103—that could allow an unauthenticated remote attacker to achieve remote code execution under specific conditions. One affects Security Gateways; the other affects both Gateways and the Security Management Server.

The company discovered the issues itself, has no evidence of in-the-wild exploitation, and began shipping fixes on September 9.

Key takeaway / Actionable note: Deploy the Check Point patches for both CVEs promptly on affected gateways and management servers.

Summary: Trezor reported that phishing campaigns targeting its customers leveraged email addresses obtained from a breach of its third-party email provider Brevo. Approximately 347,000 addresses were targeted, with about 2,500 users clicking malicious links.

Key takeaway / Actionable note: Trezor users should treat any unexpected emails with extreme caution, verify communications through official channels, and enable all available account protections.

Summary: A Ukrainian national was sentenced to four years in a U.S. prison for his role as a developer and participant in Conti ransomware attacks between 2021 and 2022. Conti targeted more than 1,000 organizations globally before the group disbanded.

Key takeaway / Actionable note: Continued law-enforcement pressure on ransomware operators remains a meaningful disruption vector even years after group dissolution.

Also Noted:

Bottom line: The past 24 hours underscore the speed at which both nation-state and financially motivated actors are weaponizing recently disclosed or patched network-appliance and print-management flaws, often with AI assistance accelerating exploit development and scale.

Prioritize internet-facing management interfaces (Cisco FMC, PaperCut, Artifactory, Check Point VPN) and treat any delayed patching as high residual risk. Identity-data exposure via third-party verification providers continues to create long-tail fraud risk.

Reply

Avatar

or to participate