Cyber Threat Brief
Avsnitt

2026-09-01: PaperCut flaws escalate from scanning to hands-on exploitation with September 14 CISA deadline

Dela

Show Notes - 2026-09-01

Stories Covered: - Today: - PaperCut NG/MF Authentication Bypass and RCE (CVE-2026-81578, CVE-2026-82078) (https://www.cisa.gov/news-events/alerts/2026/08/31/cisa-adds-two-known-exploited-vulnerabilities-catalog) - Ruby on Rails KindaRails2Shell (CVE-2026-66066) (https://thehackernews.com/2026/09/attackers-exploit-critical-langflow-and.html) - Langflow Code Execution (CVE-2026-0768) (https://thehackernews.com/2026/09/attackers-exploit-critical-langflow-and.html) - JFrog Artifactory Authentication Bypass (CVE-2026-82329) (https://www.securityweek.com/critical-jfrog-artifactory-vulnerability-reportedly-exploited-in-the-wild/) - ServiceNow AI Platform Code Injection (CVE-2026-18885, CVE-2026-18886, CVE-2026-74820) (https://research.checkpoint.com/2026/31th-august-threat-intelligence-report/) - Aurora Ransomware Uses Cursor AI for Active Directory Exploitation (https://thehackernews.com/2026/08/aurora-ransomware-operators-use-cursor.html) - Cardiology Associates of Port Huron - 150,000+ Patient Records (https://databreaches.net/2026/08/31/times-up-ransomware-group-claims-150000-cardiology-patient-records-weve-seen-the-data/) - Blossom Health Extortion Attempt (https://databreaches.net/2026/08/31/a-rough-day-at-the-extortion-office-and-a-botched-attack-on-blossom-health/) - TerminalFix Campaign - Fake Cloudflare CAPTCHA Delivers Reverse Tunnel Implant (https://thehackernews.com/2026/08/weekly-recap-chinese-spy-proxy-ai.html) - Spring Ring - Microsoft Teams Vishing Targeting 150+ Employees (https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/) - BREEZE COMET (UNC5669) Targets Brazilian Financial Services (https://cloud.google.com/blog/topics/threat-intelligence/financially-motivated-threat-actor-breeze-comet-targets-brazil/) - Fire Ant (UNC3886) Hijacks Cisco Routers, TACACS Servers (https://thehackernews.com/2026/08/china-linked-fire-ant-hijacks-cisco.html) - ZBT Router Backdoors - SPEAKINGSTONE and DARKLANTERN (https://thehackernews.com/2026/08/weekly-recap-chinese-spy-proxy-ai.html) - Hugging Face Incident - AI Agents Achieve Domain Admin in 40 Minutes (https://www.securityweek.com/what-the-hugging-face-incident-teaches-security-leaders-about-ai-agent-access/) - Anthropic Claude Code Users Hit by Infostealer Attacks (https://www.darkreading.com/cyberattacks-data-breaches/anthropic-users-infostealer-attacks-session-thefts) - Manchester Airports Group Data Breach - 8.7 Million Customers (https://research.checkpoint.com/2026/31th-august-threat-intelligence-report/) - ATF Cyberattack - Qilin Ransomware (https://research.checkpoint.com/2026/31th-august-threat-intelligence-report/) - Boston Scientific Network Outages (https://research.checkpoint.com/2026/31th-august-threat-intelligence-report/) - McKesson Data Breach - 284 Million Patient Records (https://research.checkpoint.com/2026/31th-august-threat-intelligence-report/) - Mirage Kitten Targets Aviation and FinTech with NodeRabbit and PollCat (https://securelist.com/mirage-kitten-new-backdoors-noderabbit-pollcat/121244/) - ValleyRAT Backdoor in Signed Chinese Adware (https://thehackernews.com/2026/08/valleyrat-backdoor-hides-in-signed.html) - UAC-0099 GuardBreaker - Nuclear Weapon Prompt in Malware (https://thehackernews.com/2026/09/russia-aligned-uac-0099-plants-nuclear.html) - Guildma (Astaroth) Malware via Brazilian Portuguese Email (https://isc.sans.edu/diary/rss/33300) - AI Model Prompt Injection in Legal Filing (https://www.schneier.com/blog/archives/2026/08/hiding-prompt-injection-in-legal-filing.html) - Rogue LLM Endpoint Honeypot - Coding Agent Session Exposed (https://isc.sans.edu/diary/rss/33298) - Cryptographic Context Injection in AI Assistants (https://research.checkpoint.com/2026/31th-august-threat-intelligence-report/) - Amazon Kiro Prompt Injection (Fixed) (https://research.checkpoint.com/2026/31th-august-threat-intelligen ...

Podden och tillhörande omslagsbild på den här sidan tillhör Carolina Clear Tech, LLC. Innehållet i podden är skapat av Carolina Clear Tech, LLC och inte av, eller tillsammans med, Poddtoppen.