'TerminalFix' Campaign Weaponizes PowerShell for Enterprise Attacks

A new campaign dubbed 'TerminalFix' has been identified, utilizing PowerShell to conduct sophisticated, multistage attacks against enterprise networks. This campaign employs reverse tunnels to establish persistent access into compromised victim environments.

Windows bug incorrectly tells users that Microsoft Defender Antivirus is turned off

Microsoft has identified a bug in Windows that incorrectly reports Microsoft Defender Antivirus as turned off, despite it functioning normally. This issue affects various Windows versions and is being addressed by Microsoft, but industry experts express concern that it could train users to ignore critical security alerts, making them more vulnerable to attacks.

The Coding-Agent Trap: When a "Free" LLM Endpoint Is the Adversary, (Mon, Aug 31st)

An internet-exposed inference honeypot was discovered and incorporated into infrastructure providing "free" LLM backends. The honeypot then received a real coding-agent session, exposing its history, filesystem output, and tool manifest to the adversary. This incident highlights the potential risks when seemingly free LLM services are compromised and used for malicious purposes.

OpenClaw 2.0 pours glitter on slow-burning security dumpster fire

OpenClaw 2.0, a popular agent harness, has released version 2.0 with an easier installation process and a new user interface. However, the article suggests that the core security features still rely heavily on user configuration, potentially leading to increased security issues.

Microsoft warns of TerminalFix attacks deploying reverse tunnels

Microsoft has identified a new malware campaign called TerminalFix that leverages fake Cloudflare CAPTCHA pages on compromised websites. Victims are tricked into executing malicious PowerShell commands within Windows Terminal, which then establishes reverse tunnels for attackers.

Doxxing Safety Pt I: Prevention and Footprint Management

This article is the first part of a two-part series on doxxing safety, focusing on prevention and managing one's digital footprint. It explains doxxing as the deliberate disclosure of personal information for harassment and highlights the need for individual protection due to a lack of comprehensive data privacy legislation. The article introduces Open Source Intelligence (OSINT) as a methodology central to doxxing, but also valuable for prevention, and suggests various OSINT tools and resources.

Doxxing Safety Part II: Incident Response

This article, the second part of a series on doxxing safety, focuses on incident response after personal information has been deliberately shared to harass or endanger someone. It emphasizes the importance of maintaining an incident log to track suspicious online activity and assigning team roles for a coordinated response.

File servers are here to stay. Here’s how to manage them securely

File servers continue to be essential in IT infrastructures, but managing their access permissions securely presents challenges due to accumulation over time. tenfold Software provides five best practices to streamline file server administration and enforce least-privilege access.

ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions

A threat actor named Silver Fox is distributing a backdoor called ValleyRAT. This malware is disguised as a signed Chinese adware application, specifically a legitimate desktop wallpaper tool called QN Wallpaper. By masquerading as trusted software, the attackers aim to bypass antivirus detections, particularly when users have added such applications to their antivirus exclusion lists.

Hiding Prompt Injection in Legal Filing

A legal filing has been discovered to contain hidden AI instructions, a technique known as prompt injection. This method was used to attempt to influence the AI's output and side with the party that submitted the filing. The discovery highlights novel ways malicious actors might leverage AI systems.

Trusted Chrome, Edge extensions weaponized in supply chain campaign

Attackers have weaponized legitimate browser extensions for Chrome and Edge by acquiring them from publishers and injecting malicious code through updates. This campaign affected 19 extensions, some with tens of thousands of users, and enabled the theft of cryptocurrency and sensitive user data.

More Details Emerge on Exploited PaperCut Vulnerabilities

PaperCut has issued a second emergency patch to address exploited vulnerabilities, now identified as CVE-2026-82078 and CVE-2026-81578. These patches are critical for organizations using PaperCut software.

Chrome Web Store extensions caught stealing crypto, browser data

Multiple extensions available on the Chrome Web Store have been found to contain a malware framework. This framework deploys modules designed to steal cryptocurrency, sensitive user data, and browser history, and also injects deceptive 'ClickFix' lures.

TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor

Microsoft has disclosed details of a new malware variant called TerminalFix, which tricks users into running malicious commands within Windows Terminal or PowerShell. This variant is a successor to ClickFix, employing a similar technique but targeting more modern command-line interfaces to increase the likelihood of successful execution.

YARA-X 1.20.0 Release, (Sun, Aug 30th)

The YARA-X project has released version 1.20.0, which includes 14 improvements and 13 bug fixes. YARA-X is a security tool used for threat hunting and malware analysis.

Brave browser adds email aliases to help users evade tracking

The latest version of the Brave browser, 1.94, has introduced a new feature called 'Email Aliases'. This feature allows users to generate disposable email addresses for signing up to new services, aiming to help users evade tracking.

PaperCut releases second emergency patch for exploited flaws

PaperCut has issued a second emergency security update addressing two actively exploited vulnerabilities in its print management software. This comes after initial fixes were found to be bypassable, indicating ongoing exploitation and the need for prompt patching by affected organizations.

Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication

Attackers are exploiting a newly patched security flaw in PaperCut NG and MF to execute arbitrary code remotely. PaperCut has released an emergency fix to address this vulnerability which allows unauthenticated attackers to gain control over the application's configuration.

AI Is Accelerating Vulnerability Discovery. Can Defenders Keep Up?

Artificial intelligence is significantly speeding up the discovery of software vulnerabilities. This rapid pace is outpacing traditional systems designed for vulnerability enrichment, prioritization, and remediation. Defenders must adapt by correlating diverse intelligence sources to achieve faster remediation.

You Need Cyber Deception for OT

The article highlights the challenges of responding to OT cyberattacks due to a lack of data, trails, and history. It suggests that cyber deception techniques are necessary to address these gaps.

Key Reasons Why Identity Fabric Matters in 2026

An Identity Fabric integrates disparate identity systems to provide a unified view of identity behavior across various applications, APIs, and infrastructure. As enterprises adopt more cloud services and automated workloads, maintaining identity security increasingly relies on real-time visibility rather than static configurations.

PaperCut Releases Emergency Patch for Exploited Zero-Day

PaperCut has released an emergency patch for a zero-day vulnerability affecting its NG/MF products. Users are strongly advised to install the patch and implement provided mitigations, as the vulnerability is being actively exploited.

PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions

PaperCut has issued an alert regarding a zero-day vulnerability actively being exploited in its PaperCut NG and PaperCut MF print management software. The company has released an emergency patch for versions v25 and v26 to address the critical issue, acknowledging confirmed customer incidents.

CTEM can give your security team a contextual edge

Continuous Threat Exposure Management (CTEM) is an emerging approach that moves beyond traditional vulnerability management by continuously assessing an organization's entire risk exposure. It expands scope to include misconfigurations, identity risks, and excessive permissions, and focuses on validating exploitability and assigning responsibility for remediation.

Some Malicious PE Stats, (Thu, Aug 27th)

A cybersecurity analyst is sharing statistics on compilers used to generate malicious Portable Executable (PE) files, following up on previous data about 64-bit vs. 32-bit malware trends. They developed a Python script utilizing the pefile library to extract metadata from PE headers, noting that tools like Detect It Easy can also access this information.

Why SpecterOps Signed OpenAI’s Call for Collective Cyber Defense

SpecterOps has publicly signed OpenAI's call for enhanced collective cyber defense, agreeing with three core principles. These principles emphasize the existence of current weaknesses, the need for advanced AI to be more accessible to defenders, and the necessity of a unified, widespread response to cyber threats.

Omarchy distro gains serious backing

Omarchy, a controversial Linux distribution, has secured significant funding, with tech heavyweights investing $10 million. The distribution is known for its unique approach to system design and has garnered both strong support and criticism within the tech community.

PaperCut warns of NG, MF flaw exploited in zero-day attacks

PaperCut has issued a warning that attackers are actively exploiting a zero-day vulnerability affecting all versions of its PaperCut NG and PaperCut MF print management software. This flaw is being leveraged in ongoing attacks, prompting an urgent alert for users to update their systems.

Cleartext Credential Recovery in ServiceNow

This article details a method for recovering cleartext credentials within ServiceNow, a popular IT service management platform. It explains how script includes can be utilized to create a mechanism for retrieving any discovery or LDAP credential type.

Schrödinger's backup: not actually recovered until you try to restore IT

This article emphasizes the critical importance of testing backups to ensure their recoverability. It highlights that a backup is only truly valuable if a successful restore can be performed, urging organizations to regularly verify their data recovery capabilities.

Claude, Codex, and Hermes installed unowned code inside corporate networks

A recent analysis uncovered 227 install commands within corporate documentation that point to code without clear ownership. This situation raises significant security concerns, as it implies the potential for unauthorized or malicious software to be deployed within organizational networks.

How Threat Research and MDR Help SMBs Build a Defensive Edge

This article explains how threat research and Managed Detection and Response (MDR) can bolster the defenses of Small and Medium-sized Businesses (SMBs). It highlights that combining threat intelligence with continuous monitoring and human expertise enables faster detection and response to cyber threats.

Learn How to Build Security Operations Ready for AI-Powered Attacks

Advanced AI models are accelerating the attack lifecycle, enabling threat actors to discover vulnerabilities, generate exploit code, and move through networks faster. This shift challenges traditional security operations, which were designed for slower attack speeds. Security teams must adapt their strategies to address the reduced time available for response.

AI can be made to read an email much differently than you do

Security researchers from Forcepoint X-Labs have demonstrated a method where invisible HTML can be embedded in emails, causing AI email summarizers to interpret them as instructions. This technique allows the AI to process one version of an email while the user sees a different, seemingly benign version, potentially leading to compromised information or actions.

'HTTP Terminator' Hunts for Novel Desync Attacks

James Kettle from PortSwigger has developed an open-source, AI-powered tool named 'HTTP Terminator.' This tool is designed to discover novel HTTP request-smuggling techniques by identifying new desync attacks.

Who Has Admin Rights in your Entra ID Directory?, (Wed, Aug 26th)

This article discusses the importance of managing administrative rights within Entra ID (formerly Azure AD) to prevent unauthorized access or modifications. It highlights the risks associated with former employees retaining privileges and the common issue of having too many administrators with excessive permissions, noting this is a key security control.

Hackers target Microsoft SharePoint RCE chain with PoC exploit

Attackers are exploiting a chain of two Microsoft SharePoint vulnerabilities that can lead to remote code execution on unpatched servers. Threat intelligence indicates that proof-of-concept exploits are already in circulation, increasing the risk for organizations using vulnerable SharePoint versions.

Adobe and Nvidia Patch Dozens of Vulnerabilities

Adobe and Nvidia have released multiple security advisories, detailing fixes for numerous vulnerabilities within their respective products. Several of these addressed vulnerabilities have been classified as critical.

CISA Vulnerability Review

CISA's Vulnerability Review analyzes data from FY2024 and FY2025 to identify common software weaknesses and provide practical steps for organizations to prevent exploitation. The review emphasizes the importance of Secure by Design principles and offers a framework for prioritizing vulnerabilities based on risk, using criteria such as exposure status, KEV Catalog status, automated exploit potential, and technical impact.

Imagine the SOC Without a Queue: From Alert Backlog to AI Hypothesis Engine

Traditional Security Operations Centers (SOCs) are overwhelmed by alert volume, leading to many alerts never being reviewed by analysts. This article proposes shifting from a queue-based model to an AI hypothesis engine that can automate the initial stages of alert triage and investigation.