CYBER_THREATCAST
$ briefing --date=
CYBER THREATCAST
CYBER THREAT INTELLIGENCE BRIEFING
PaperCut warns that an unassigned zero-day affecting every PaperCut NG and MF version is under active exploitation. Elsewhere, attackers exploited ownCloud and a deprecated Rain smart contract, while intrusions affected Norwegian public services and CareCloud’s AWS environment.
PaperCut has released emergency patches for versions 25 and 26 and published compromise indicators. With every NG and MF version affected, organizations should promptly assess exposed installations for compromise and apply the available fixes.
Unpatched software, deprecated code and compromised credentials continue to provide direct routes into sensitive systems. QTFY combines vulnerability exploitation with credential theft, infostealers hijack Claude sessions, and a compromised employee account enabled access to Hasbro’s network.
Editorial: Recommended Actions
01
PRIORITY
Patch PaperCut MF and NG immediately using the emergency releases for versions 25 and 26, and review PaperCut’s compromise indicators for evidence of intrusion. Every version is affected by the unassigned zero-day, which attackers are actively exploiting; organizations on older releases should prioritize moving to a patched version.
02
PRIORITY
Patch internet-facing ownCloud systems against CVE-2023-49105 and other outstanding ownCloud vulnerabilities, then investigate file-access records for possible theft. A Chinese-speaking operator exploited unpatched instances to target Philippine nuclear and naval organizations, with logs indicating that roughly 9 GB may have been stolen.
03
PRIORITY
Confirm that platforms using Rain have received the upgrade, retire deprecated Rain smart contracts, and review collateral-wallet administrator changes and signed authorization activity. The attacker repeatedly submitted signed authorizations to add administrative access, stealing about $1.1 million from Avici and Tria before moving funds through Solana, Ethereum, and Tornado Cash.
04
PRIORITY
Update affected WordPress installations immediately, prioritizing Avada through 7.16, Fusion Builder through 3.16, GiveWP through 4.16.7.1, Pods through 3.3.9, TranslatePress through 3.3.1, and WPMU DEV Dashboard through 5.0.1. The five flaws rate as high as CVSS 10.0 and can enable site takeover or remote code execution; GiveWP’s CVE-2026-82222 can execute arbitrary commands.
05
PRIORITY
Block and investigate unauthorized ClaudeDesktop.exe downloads, hunt Windows endpoints for SectopRAT and DLL sideloading, and revoke Claude sessions associated with suspected infections. FakeAgent generated about 7,100 downloads in two days and affected at least 29 organizations, while infostealers can steal active Claude session cookies to bypass passwords and MFA and consume paid usage.
ROUNDTABLE
Expert Panel Discussion
12 AI experts analyzed this briefing across 3 turns of structured debate
12Agents14Messages15mDuration
→
Field Signals
Real-time intelligence from X/Twitter
$ scanning feeds_