Summary: Two critical flaws in PaperCut NG and MF (CVE-2026-81578 and CVE-2026-82078) that can be chained for authentication bypass and remote code execution are being actively abused for data theft. PaperCut released three emergency patches after zero-day exploitation; Defused observed attackers using the auth bypass to dump database tables via Derby rather than pure RCE. CISA added both CVEs to its Known Exploited Vulnerabilities catalog; federal agencies must remediate by September 14. Over 800–1,000 instances remain internet-exposed.
Key takeaway / Actionable note: Immediately apply PaperCut Emergency Patch Release 3 (or later), assume any previously internet-facing unpatched server is compromised, and hunt with the vendor’s latest IoCs for remote-access tools and data exfiltration.
Summary: Threat actors are exploiting CVE-2026-0768 (CVSS 9.8), an unauthenticated remote code execution flaw in the Langflow AI low-code platform’s code validator that allows arbitrary Python execution as root. VulnCheck reports reconnaissance and credential harvesting (environment variables, secret keys, SSH) primarily from Russian infrastructure, with hundreds of exploitation attempts observed against canaries. All versions up to 1.4.2 are affected; the flaw was publicly disclosed as a zero-day earlier in 2026.
Key takeaway / Actionable note: Patch Langflow immediately or isolate instances; monitor for unusual Python execution and credential-access patterns on AI development platforms.
Summary: CVE-2026-82329, a critical authentication-bypass vulnerability in JFrog Artifactory that can grant administrative access under default configuration, is being exploited in the wild days after disclosure. WatchTowr observed attackers minting admin tokens. Patches are available in multiple self-hosted versions (including 7.111.21 and later listed releases); cloud instances were already updated by JFrog.
Key takeaway / Actionable note: Upgrade self-hosted Artifactory to a patched version without delay and review recent administrative token creation and repository activity.
Summary: Healthcare technology company Aesto Health reported that attackers accessed portions of its AWS infrastructure between December 2–18, 2025, exfiltrating PII and PHI belonging to 9,540,683 individuals. Stolen data includes names, Social Security numbers, driver’s license numbers, dates of birth, financial account numbers, medical and health-insurance information, and taxpayer IDs. Multiple client healthcare providers across states are affected; HHS has been notified.
Key takeaway / Actionable note: Organizations using Aesto Health or similar legacy-data/EHR services should monitor for identity-theft indicators and ensure breach notifications and credit-monitoring offers reach impacted individuals.
Summary: Nutex Health confirmed in an SEC filing that unauthorized parties accessed its network and stole patient, employee, provider, business, and financial information. The Gentlemen (Storm-2697) ransomware group claimed responsibility and listed the company on its leak site with a short deadline. Nutex reported no material impact to operations or financial reporting systems to date and faces at least one purported class-action complaint.
Key takeaway / Actionable note: Healthcare operators should review third-party and internal access controls and prepare for rapid double-extortion response playbooks.
Summary: WatchGuard released patches for more than two dozen vulnerabilities, including five critical issues (CVSS 9.3) that enable unauthenticated remote code execution. Three affect the Fireware OS iked process (heap/stack buffer overflows and type confusion in IKE handling); another impacts the Endpoint Protection Manager service; a fifth allows session-ID/CSRF token theft in Dimension. Fixes ship in Fireware OS 2026.2.2 / 12.12.2 / 12.5.20 and Dimension 2.3.1. No in-the-wild exploitation is known.
Key takeaway / Actionable note: Prioritize patching of internet-facing Fireware OS and Dimension instances, especially those handling IPsec VPN.
Summary: The China-nexus actor Fire Ant (overlapping with UNC3886 reporting) has expanded from VMware hypervisors to compromise Cisco IOS XR routers, TACACS servers, and Linux management hosts. Compromised routers were turned into traffic-collection platforms; logging and telemetry were suppressed; a new TACACS credential harvester (TacTap) and Linux backdoor (BridgeAgent) were deployed. Activity included scanning toward critical infrastructure but confirmed compromise remained limited to the edge devices.
Key takeaway / Actionable note: Treat routers, TACACS, hypervisors, and jump hosts as high-value forensic assets; validate configurations and logs against memory and network evidence, and hunt for the published IoCs (including GRE tunnels without commit history and TacTap artifacts).
Summary: Microsoft detailed a ClickFix variant called TerminalFix that presents fake Cloudflare CAPTCHA overlays on compromised sites, prompting users to paste multi-line PowerShell into Windows Terminal. The multi-stage chain uses DLL sideloading, steganographic PNG payloads, persistence via Run keys and scheduled tasks, Active Directory reconnaissance, and a Python-based reverse WebSocket tunnel (gitnow[.]dev:443) that provides SOCKS-style internal network access.
Key takeaway / Actionable note: Restrict and log PowerShell/Terminal execution, monitor for LockScreenContentServer.exe outside expected paths, and treat any confirmed infection as a potential network pivot requiring credential rotation and lateral-movement hunting.
Summary: Huntress documented five confirmed 2026 cases of DPRK-aligned workers (tracked as FAMOUS CHOLLIMA) obtaining legitimate remote jobs in IT, sales, marketing, and healthcare using stolen or fabricated identities, travel routers, PiKVM hardware, proxies, and screen-sharing tools. Workers often perform real duties while remitting earnings; detection relies on correlating document forensics, hardware indicators, and behavioral anomalies rather than traditional network IOCs.
Key takeaway / Actionable note: Strengthen pre-hire identity verification, background checks, and post-hire monitoring for KVM devices, unusual proxy use, and identity-document anomalies, especially for fully remote roles.
Summary: Five Venezuelan nationals pleaded guilty to conspiracy to commit bank larceny after attempting (unsuccessfully) to install malware on ATMs in Kansas to force cash dispensation. The FBI continues to note rising ATM jackpotting activity nationwide.
Key takeaway / Actionable note: Financial institutions should maintain physical and logical controls on ATM software and monitor for anomalous cash-dispensing patterns.
Also Noted:
Bottom line: The last 24 hours underscore how quickly zero-days in widely deployed enterprise software (PaperCut, Langflow, JFrog Artifactory) move from disclosure to active data-theft and access operations, while nation-state actors continue refining both technical (router/TACACS) and non-technical (insider hiring) vectors. Prioritize emergency patching of internet-facing print, AI, and artifact-management platforms, assume compromise where exposure windows existed, and tighten identity and hardware verification for remote workers.

