CYBER_THREATCAST
$ briefing --date=
CYBER THREATCAST
CYBER THREAT INTELLIGENCE BRIEFING
Attackers are chaining CVE-2026-81578 and CVE-2026-82078 for unauthenticated remote code execution in PaperCut NG/MF, prompting CISA to add both flaws to its Known Exploited Vulnerabilities catalog. Emergency Patch Release 2 is the immediate priority. AI coding agents are also executing attacker-controlled packages through dangling llms.txt references, while weak verification and collateral-pricing controls are driving major DeFi losses.
About 1,000 PaperCut instances were reportedly internet-accessible, and a proposed Metasploit module demonstrated SYSTEM-level access against versions 24.x through 26.x. Organizations running PaperCut NG/MF should deploy Emergency Patch Release 2 without delay.
Researchers found 120 llms.txt files with 227 references to unregistered packages or expired domains, including a Clerk-themed name reportedly loaded with malware. Aave plans to shut deployments on six networks and LayerZero dropped 32 chains after infrastructure concerns, while More Markets lost about $9.3 million and a reported Coldcard entropy weakness was linked to the theft of roughly 1,816 bitcoin.
Editorial: Recommended Actions
01
PRIORITY
Install PaperCut Emergency Patch Release 2 on all PaperCut NG/MF 24.x through 26.x systems immediately, prioritizing internet-accessible instances. Attackers are actively chaining CVE-2026-81578 and CVE-2026-82078 for unauthenticated remote code execution, and a proposed Metasploit module demonstrates SYSTEM-level access.
02
PRIORITY
Remediate Linux kernel IPv6 CVE-2026-53362 and JFrog Artifactory CVE-2026-66384 under applicable CISA KEV deadlines. Investigate affected Kubernetes environments for root access, misuse of service accounts or cloud credentials, egress, and lateral movement—the same attack paths observed against Hugging Face and OpenAI infrastructure.
03
PRIORITY
Restrict access to VMware vCenter Server Appliance and remediate CVE-2026-59309 and CVE-2026-59310 immediately. Review systems for authentication bypass, unauthenticated root-level code execution, and Babuk ransomware activity; exploitation was observed beginning around August 3, 2026.
04
PRIORITY
Identify Ruby on Rails applications exposed to CVE-2026-66066 and urgently review Active Storage upload handling. Treat Rails 8.1.3.1 as potentially exposed when attackers possess a valid signature, because crafted uploads can disclose files, secrets, and credentials and enable lateral movement or remote code execution.
05
PRIORITY
Audit corporate llms.txt files now for unregistered package names and expired domains, then remove or correct dangling references before allowing Claude, Codex, Hermes, or other coding agents to use them. Researchers found 227 dangling references in 120 files and observed enterprise agents retrieve and execute attacker-registered packages; a Clerk-themed package was reportedly loaded with malware.
Field Signals
Real-time intelligence from X/Twitter
$ scanning feeds_