Why Should I Care? β 2026-09-01 | π΄ 1 HIGH Β· π‘ 1 MEDIUM Β· π΅ 21 RADAR Β· βͺ 47 FILTERED
π Briefing β 2026-09-01
23 vendor intel items scanned | π΄ 1 HIGH | π‘ 1 MEDIUM | π΅ 21 RADAR | βͺ 47 FILTERED
π΄ Critical β action required:
- CISA Adds Two Known Exploited Vulnerabilities to Catalog (CVE-2026-81578, CVE-2026-82078) β Yes, if you run PaperCut NG/MF versions affected by CVE-2026-81578 or CVE-2026-82078: these vulnerabilities can be exploited by attackers to gain unauthorized access or execute arbitrary code.
Everything else can wait.
π‘ Medium β review when time permits:
- Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams β Yes, if you use Microsoft Teams for internal support communications: this campaign leverages voice phishing to deploy malware and target domain controllers.
π΅ 15 items on the radar β see below β
Why Should I Care? π΄ HIGH β Handle Now
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA Advisories [CISA KEV] | CVE-2026-81578, CVE-2026-82078
β Why Should I Care?
Yes, if you run PaperCut NG/MF versions affected by CVE-2026-81578 or CVE-2026-82078: these vulnerabilities can be exploited by attackers to gain unauthorized access or execute arbitrary code.
π― Affected versions: PaperCut NG/MF versions prior to 20.1.3
Not affected: 20.1.3 and later
π In plain English:
These vulnerabilities allow attackers to bypass authentication or execute arbitrary code, potentially taking full control of your PaperCut NG/MF system. For example, an attacker could log in without credentials or run malicious software on your server.
π§ Prerequisites:
- Running PaperCut NG/MF versions prior to 20.1.3
- Network access to the vulnerable system
β± Urgency: High urgency due to active exploitation and the risk of unauthorized access or system compromise.
β Fixed in: 20.1.3
π‘ Context: The root cause involves missing authentication checks and unsafe reflection, allowing attackers to exploit these vulnerabilities.
Why Should I Care? π‘ MEDIUM (1)
Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams
Palo Alto Unit 42
β Why Should I Care?
Yes, if you use Microsoft Teams for internal support communications: this campaign leverages voice phishing to deploy malware and target domain controllers.
π― Affected versions: All versions of Microsoft Teams that support external chat creation
π In plain English:
Attackers are using Microsoft Teams to impersonate IT support and trick employees into running malicious software. They make voice calls to convince users to install tools that can take over your network.
π§ Prerequisites:
- Microsoft Teams is used for internal support communications
- External chat creation is enabled
β± Urgency: High urgency due to the potential for domain controller compromise, which can lead to full network control.
π‘ Context: The root cause is the exploitation of trust in communication platforms and the human tendency to comply with perceived authority figures.
Why Should I Care? π΅ On the Radar (21)
- Microsoft Exchange Online outage causes email failures, auth issues (BleepingComputer) β Microsoft is dealing with a major outage affecting Exchange Online and other Microsoft 365 services, causing email failures, authentication issues, and delays. This impacts tens of thousands of users.
- Berlin confirms data theft after Rhysida ransomware attack claims (BleepingComputer) β Berlin's city administration was hit by Rhysida ransomware, leading to a massive data theft. This attack highlights the vulnerability of government and critical infrastructure to ransomware attacks, with potential impacts on data confidentiality and operational integrity.
- Chinese Fire Ant hackers turn Cisco routers into spying platforms (BleepingComputer) β Fire Ant hackers are using a sophisticated method to turn Cisco routers into spying platforms by creating hidden GRE tunnels and deploying custom malware. This can allow them to capture and exfiltrate sensitive network traffic.
- Chrome Web Store extensions caught stealing crypto, browser data (BleepingComputer) β Malicious extensions in Chrome and Edge were stealing cryptocurrency and sensitive data. This affects users who have installed these extensions, potentially compromising their accounts and wallets.
- Anthropic warns infostealer malware is hijacking Claude sessions to drain usage (BleepingComputer) β Infostealer malware is stealing active login sessions for Claude, allowing attackers to access accounts and use up user quotas. This affects users who have been infected with common malware.
- FulcrumSec claims Manchester Airports hack, theft of 86 GB of data (BleepingComputer) β A hacking group, FulcrumSec, claims to have stolen 86 GB of data from Manchester Airports Group, including detailed customer and travel information. This breach shows that airport IT systems are vulnerable to sophisticated attacks and could lead to significant data exposure and loss of customer trust.
- Microsoft warns of TerminalFix attacks deploying reverse tunnels (BleepingComputer) β A new attack called TerminalFix uses fake CAPTCHA prompts to trick users into running malicious PowerShell commands in Windows Terminal, leading to a reverse tunnel that can be used for various malicious activities like data exfiltration or deploying ransomware.
- Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets (The Hacker News) β Aurora ransomware operators are using SpaceX's Cursor AI to plan and execute attacks on at least 10 targets. This means that if you use Cursor AI or manage systems that could be targeted by ransomware, you need to be aware of the risks and take precautions.
- ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions (The Hacker News) β A sophisticated backdoor called ValleyRAT is being distributed disguised as a legitimate Chinese adware application, QN Wallpaper. The malware takes advantage of users who add trusted software to antivirus exclusions, allowing it to bypass security controls.
- Cronos blockchain restarts after $74 million Tectonic exploit (BleepingComputer)
- North Korean Job Fraud Expands Beyond IT Into Healthcare and Sales (The Hacker News) β Reports on expanded North Korean job fraud beyond IT into healthcare and sales.
- Automate IAM Identity Center governance with continuous discovery and reporting (AWS Security Blog) β Blog post about automating IAM Identity Center governance.
- We invited a direct competitor into Security Hub Extended. Hereβs why. (AWS Security Blog) β Blog post about integrating a competitor's solution into AWS Security Hub Extended.
- β‘ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and More (The Hacker News) β Weekly security news recap.
- File servers are here to stay. Hereβs how to manage them securely (BleepingComputer) β Best practices for secure file server administration.
βͺ 47 low-priority items filtered.
π¦ Aggregated and triaged by Donna AI | Sources: 8 vendor feeds | CISA KEV