Cyber Threat Brief
Avsnitt

2026-08-29: PaperCut NG/MF is under active exploitation with a pre-auth RCE chain -- patch immediately or pull

Dela

Show Notes - 2026-08-29

Stories Covered: - Today: - PaperCut NG/MF Pre-Auth RCE -- Active Exploitation (CVE-2026-81578, CVE-2026-82078) (https://www.huntress.com/blog/papercut-actively-exploited) - ownCloud WebDAV Auth Bypass Exploited to Steal Nuclear Records (CVE-2023-49105) -- CISA KEV Due Aug 30 (https://thehackernews.com/2026/08/snowflake-github-actions-flaw-lets.html) - China-Made ZBT Routers Ship With Factory Backdoor Implants (CVE-2026-66747, CVE-2026-74232, CVE-2026-74233) (https://thehackernews.com/2026/08/china-made-zbt-routers-ship-with-two.html) - ATF Confirms "Major Incident" After Qilin Ransomware Claim (https://www.securityweek.com/atf-confirms-cyber-incident-after-ransomware-group-claims-attack/) - Winona County Pays $128K Ransom (https://databreaches.net/2026/08/28/winona-county-paid-more-than-128k-following-january-ransomware-attack/) - U.S. Bancorp Responds to LockBit Claims (https://www.securityweek.com/in-other-news-log4j-rce-scare-minimus-shutdown-iranian-hacker-sanctions/) - Paylogix Breach Exposes SSNs, Medical Data, Passport Numbers (https://www.securityweek.com/in-other-news-log4j-rce-scare-minimus-shutdown-iranian-hacker-sanctions/) - 700+ Active AWS Keys Found Exposed (https://www.securityweek.com/in-other-news-log4j-rce-scare-minimus-shutdown-iranian-hacker-sanctions/) - Cybersecurity Firm Minimus Shuts Down (https://www.securityweek.com/in-other-news-log4j-rce-scare-minimus-shutdown-iranian-hacker-sanctions/) - Microsoft Edge and Chromium Security Updates (https://msrc.microsoft.com/update-guide/) - Log4j RCE Scare Deemed Overblown (https://www.securityweek.com/in-other-news-log4j-rce-scare-minimus-shutdown-iranian-hacker-sanctions/) - Mobile Banking Malware Expands (https://www.securityweek.com/in-other-news-log4j-rce-scare-minimus-shutdown-iranian-hacker-sanctions/) - Russian Cyber Training Pipeline Exposed (https://www.securityweek.com/in-other-news-log4j-rce-scare-minimus-shutdown-iranian-hacker-sanctions/) - Unitree G1 EDU Humanoid Robot -- Two Root RCE Chains (CVE-2026-76639, CVE-2026-76640) (https://thehackernews.com/2026/08/two-unitree-g1-edu-humanoid-robot-flaws.html) - Carhartt Breach Data Partly Fake (https://www.securityweek.com/in-other-news-log4j-rce-scare-minimus-shutdown-iranian-hacker-sanctions/)

CVEs Referenced: CVE-2023-49105, CVE-2024-28000, CVE-2026-53362, CVE-2026-58616, CVE-2026-66384, CVE-2026-66747, CVE-2026-70331, CVE-2026-74232, CVE-2026-74233, CVE-2026-76639, CVE-2026-76640, CVE-2026-78891, CVE-2026-78899, CVE-2026-78952, CVE-2026-81578, CVE-2026-82078

Indicators of Compromise: Domains: 209[.]241, 209[.]241.

Full brief: https://carolinacleartech.com/brief/2026-08-29/

Podden och tillhörande omslagsbild på den här sidan tillhör Carolina Clear Tech, LLC. Innehållet i podden är skapat av Carolina Clear Tech, LLC och inte av, eller tillsammans med, Poddtoppen.