PaperCut Exploitation Escalates to Active Intrusions

CISA has added two vulnerabilities affecting PaperCut software, tracked as CVE-2026-82078 and CVE-2026-81578, to its Known Exploited Vulnerabilities (KEV) catalog. This addition indicates that these vulnerabilities are actively being exploited in the wild.

'TerminalFix' Campaign Weaponizes PowerShell for Enterprise Attacks

A new campaign dubbed 'TerminalFix' has been identified, utilizing PowerShell to conduct sophisticated, multistage attacks against enterprise networks. This campaign employs reverse tunnels to establish persistent access into compromised victim environments.

Microsoft warns of TerminalFix attacks deploying reverse tunnels

Microsoft has identified a new malware campaign called TerminalFix that leverages fake Cloudflare CAPTCHA pages on compromised websites. Victims are tricked into executing malicious PowerShell commands within Windows Terminal, which then establishes reverse tunnels for attackers.

Anthropic cracks down on hijacked user accounts mining AI tokens

Anthropic is taking action against a surge of compromised user accounts being used to illicitly mine AI tokens. Commodity malware is reportedly stealing authenticated sessions, enabling attackers to exploit victims' paid AI usage.

ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions

A threat actor named Silver Fox is distributing a backdoor called ValleyRAT. This malware is disguised as a signed Chinese adware application, specifically a legitimate desktop wallpaper tool called QN Wallpaper. By masquerading as trusted software, the attackers aim to bypass antivirus detections, particularly when users have added such applications to their antivirus exclusion lists.

Anthropic Warns Claude Users of Infostealer Malware Infections

AI company Anthropic is experiencing widespread infostealer malware infections affecting its Claude AI chatbot users. The company is proactively logging users out and removing payment information to prevent unauthorized use of the service.

Trusted Chrome, Edge extensions weaponized in supply chain campaign

Attackers have weaponized legitimate browser extensions for Chrome and Edge by acquiring them from publishers and injecting malicious code through updates. This campaign affected 19 extensions, some with tens of thousands of users, and enabled the theft of cryptocurrency and sensitive user data.

Berlin Won’t Pay Extortion Group Claiming Data Theft

The Rhysida ransomware group has claimed to have exfiltrated over 5TB of data, which includes personal information and credentials. Authorities in Berlin have stated they will not pay any ransom to the extortion group.

CVE-2026-81578: PaperCut NG/MF Missing Authentication for Critical Function Vulnerability

PaperCut NG/MF has a critical vulnerability allowing unauthenticated remote attackers to modify system configurations. This flaw can be combined with another vulnerability, CVE-2026-82078, and requires immediate mitigation according to vendor instructions and CISA guidance. Its exploitation for ransomware is currently unknown.

CVE-2026-82078: PaperCut NG/MF Unsafe Reflection Vulnerability

PaperCut NG/MF has an unsafe reflection vulnerability that allows attackers to execute arbitrary Java bytecode on the server process. This flaw can be chained with another vulnerability, CVE-2026-81578, and requires immediate mitigation according to vendor instructions and CISA guidance.

Chrome Web Store extensions caught stealing crypto, browser data

Multiple extensions available on the Chrome Web Store have been found to contain a malware framework. This framework deploys modules designed to steal cryptocurrency, sensitive user data, and browser history, and also injects deceptive 'ClickFix' lures.

TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor

Microsoft has disclosed details of a new malware variant called TerminalFix, which tricks users into running malicious commands within Windows Terminal or PowerShell. This variant is a successor to ClickFix, employing a similar technique but targeting more modern command-line interfaces to increase the likelihood of successful execution.

Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE

Multiple critical security vulnerabilities have been discovered in popular WordPress plugins and themes including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP. These flaws could allow attackers to bypass authentication, take over accounts, or execute arbitrary code on affected websites.

ATF Confirms Cyber Incident After Ransomware Group Claims Attack

The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has confirmed a major cyber incident that is being investigated by the Department of Justice. This confirmation follows a claim by a ransomware group that they were responsible for the attack.

APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations

Cybersecurity researchers have identified new campaigns targeting European government and diplomatic organizations in Romania, Spain, and Türkiye between late September 2025 and early April 2026. These campaigns have resulted in the deployment of a new backdoor named HOOKEDGE, which is a lightweight Windows batch script.

Some Malicious PE Stats, (Thu, Aug 27th)

A cybersecurity analyst is sharing statistics on compilers used to generate malicious Portable Executable (PE) files, following up on previous data about 64-bit vs. 32-bit malware trends. They developed a Python script utilizing the pefile library to extract metadata from PE headers, noting that tools like Detect It Easy can also access this information.

Risky Bulletin: Two TeamPCP members arrested in Australia

Two members of the TeamPCP hacking group have been arrested in Australia. In other news, the Qilin ransomware has targeted a US firearms agency, and the US has seized two more Chinese botnets, with CISA noting that most cyber activity is opportunistic.

Australian cops cuff alleged TeamPCP masterminds

Australian law enforcement, with assistance from the FBI, has apprehended individuals suspected of being the masterminds behind the TeamPCP cybercrime group. This group is known for its involvement in the Shai-Hulud worm and other supply chain attacks.

Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks

Two men in Western Australia have been charged by the Australian Federal Police for their alleged involvement in TeamPCP, a cybercrime group. This group is believed to be responsible for compromising open-source security scanners Trivy and Checkmarx KICS, as well as the AI gateway LiteLLM.

Russian Hackers Phish EU Officials Over Messaging Apps

Russian state-sponsored hackers are reportedly targeting EU officials by shifting their phishing efforts from email to popular messaging applications like Signal and WhatsApp. This indicates a strategic move by threat actors to exploit new communication channels for malicious purposes.

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia

Australian authorities have arrested two individuals in Western Australia who are believed to be members of the cybercrime group TeamPCP. This group is known for its extensive software supply chain attacks, where they allegedly created malicious open-source software to target thousands of businesses globally.

ATF confirms “major incident” after recent Qilin breach claims

The U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has confirmed a "major incident" involving a system compromise, following claims by the Qilin ransomware gang that they breached the agency. The full scope and impact of the incident are still being investigated.

The State of Ransomware in Education 2026

A report analyzes the state of ransomware attacks in the education sector, based on insights from 226 IT and cybersecurity leaders across 17 countries. The article focuses on organizations that experienced ransomware incidents in the past year.

Dark Caracal Adds New Malware to Cyber Espionage Arsenal

Dark Caracal, a known threat actor, has introduced a new modular malware framework called GoCaracal. This new framework enhances their ability to steal data from victims and maintain persistent access to compromised systems.

Android Malware Hijacks Update System for Car Head Units

Threat actors have begun targeting vehicle infotainment systems by exploiting their update mechanisms to spread malware. This new campaign leverages a known click-fraud botnet, indicating a shift towards more sophisticated and potentially lucrative targets.

AI Speeds Up Malware Development, Not Its Success Rate: Analysis

Palo Alto Networks Unit 42 analyzed 405 malware samples created with AI assistance and discovered that only a small fraction, 12 samples, managed to reach production endpoints. This suggests that while AI may accelerate the development process, it does not necessarily increase the success rate of malware.

'NovaCookies' Kit Steals Microsoft 365 Sessions for $320 a Month

A new adversary-in-the-middle (AitM) phishing service called 'NovaCookies' is now available for $320 per month. This service significantly reduces the technical expertise required for threat actors to conduct sophisticated attacks. NovaCookies can steal active Microsoft 365 session cookies, bypassing multi-factor authentication and offering more than just credential theft.

Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload

CISA has issued a warning about active exploitation of a critical remote code execution vulnerability in Gitea, identified as CVE-2026-60004. Attackers with repository write access can execute arbitrary shell commands. The vulnerability has a CVSS score of 9.8 and is reportedly being used to drop miner-like payloads.

CVE-2015-3246: Red Hat Libuser Race Condition Vulnerability

A race condition vulnerability in Red Hat libuser (CVE-2015-3246) allows authenticated local users to corrupt the /etc/passwd file, potentially leading to denial of service or privilege escalation. Organizations are advised to apply vendor-provided mitigations and comply with CISA's guidance on prioritizing security updates.