๐จ ACTIVE EXPLOITATION
- PaperCut NG/MF flaws added to KEV after active exploitation
CVE-2026-81578CVE-2026-82078
Attackers are exploiting two PaperCut NG/MF vulnerabilities added to CISA's KEV catalog.- PaperCut NG and MF print-management servers used by enterprises, schools, and other organizations are affected.
- CVE-2026-81578 is an 8.8 authentication bypass in the web management interface.
- CVE-2026-82078 is a 9.4 unsafe dynamic class-loading flaw in database connection utilities.
- Attackers can chain the flaws to alter configurations and execute arbitrary Java bytecode as the PaperCut server process.
- PaperCut versions 24, 25, and 26 received emergency patches; all versions are potentially impacted, with pc-app.exe activity and anomalous server.log entries reported as indicators.
๐ Coverage: rapid7.com ยท ๐ via SecurityWeek
๐ต๏ธ RESEARCH & DEEP DIVES
-
Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware set
Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.
๐ Coverage: securelist.com ยท ๐ via Securelist (Kaspersky) -
Password-Spraying Campaign Targets AWS Root Accounts at 150+ Organizations
Datadog observed password-spraying attacks against AWS root accounts at more than 150 organizations.- AWS customers across multiple industries and regions were targeted.
- AWS root accounts, which have unrestricted access to cloud resources and account settings, were attacked.
- The campaign ran from July 24 to August 23, 2026, with a median of two failed attempts per organization and up to eight.
- Attackers tunneled login requests through hosting infrastructure and residential proxies across multiple countries and ASNs.
- Observed user agents included Chrome/85.0.4183.83 with Edge/85.0.564.41 and Firefox/120.0. No successful logins were identified.
๐ Source: securitylabs.datadoghq.com ยท ๐ Coverage: gbhackers.com ยท ๐ via Cyber Security News, cryptika.com (discovered)
๐ CVEs & KEV
-
CVE-2026-19806 โ CVSS 8.8 โ Support Genix through 1.4.52 - Authenticated (Subscriber+) Authentication Bypass t...
-
CVE-2026-19952 โ CVSS 7.5 โ Frontend Admin by DynamiApps through 3.29.12 - Unauthenticated Arbitrary File Dele...
-
CVE-2026-19573 โ CVSS 7.2 โ Affiliate Super Assistent through 1.10.2 - Unauthenticated Stored Cross-Site Scrip...
-
CVE-2026-75921 โ CVSS 7.2 โ Master Addons for Elementor through 3.1.9 - Incorrect Authorization to Authenticat...
-
CVE-2026-77189 โ CVSS 6.5 โ Charitable through 1.8.12.1 - Authenticated (Contributor+) SQL Injection via 'orde...
-
CVE-2026-18752 โ CVSS 6.5 โ Persistent Login through 3.1.0 - Authenticated (Subscriber+) SQL Injection via 'wp...
-
CVE-2026-18488 โ CVSS 6.4 โ Blocksy Companion through 2.1.51 - Authenticated (Author+) Stored Cross-Site Scrip...
-
CVE-2026-75980 โ CVSS 6.4 โ BetterDocs through 4.8.1 - Authenticated (Contributor+) Stored Cross-Site Scriptin...
-
CVE-2026-12747 โ CVSS 6.4 โ Frontend Admin by DynamiApps through 3.29.11 - Authenticated (Contributor+) Stored...
-
CVE-2026-13203 โ CVSS 6.4 โ Live Composer through 2.1.19 - Authenticated (Contributor+) Stored Cross-Site Scri...
-
CVE-2026-16787 โ CVSS 6.4 โ Live Composer through 2.1.19 - Authenticated (Contributor+) Stored Cross-Site Scri...
-
CVE-2026-75965 โ CVSS 6.4 โ User Profile Builder through 4.0.0 - Authenticated (Contributor+) Stored Cross-Sit...
-
CVE-2026-75964 โ CVSS 6.1 โ User Profile Builder through 4.0.0 - Unauthenticated Stored Cross-Site Scripting v...
๐ ADVISORIES
- ๐ Source for Fake Crypto AML Sites Trick Users Into Approving Wallet-Draining Transactions โ malwarebytes.com