Security News

Cybersecurity news aggregator

📰
INFO News

Security Morning Briefing - August 29, 2026

  • ## Þjónustu samantekt Þjónustuþjónustuferðin er ennþá með virkri nýtingu á áhrifaskilum í algengum fyrirtækjaskilum. **PaperCut NG/MF** og **Citrix NetScaler** eru á meðal áfangar á nýbirtum núll-daga veikleikum, sem krefjast áætlaðar uppfærslu. Stjórnendur stjórnar er hár, með **FBI að banna aðgangi á QTFY spjallneti tengdum Kína** og rússneskum aðildum sem nýta **núll-daga veikleika í Zimbra**. Auk þess, er nýjungarhugbúnaður (**ClickFix**) að nota Windows Terminal til að setja út gíslatökuhugbúnað, en ávöxt í **Microsoft Device Code Phishing** er ávextur á MFA-vernduðum reikningum. ## ⚠️ Þjónustu aðgerð
  • *PaperCut NG/MF Núll-daga auðkenningarframhjáhlaup** Einn áhrifaskil á PaperCut NG/MF útgáfum er í virkri nýtingu, sem leyfir aðildum að framhjá auðkenningu og keyra fjarkeyrslu kóða með sérstaklega samsettar HTTP POST beðnir.
  • *CVE:** CVE-2023-27350 (CVSS: Ekki tilgreint)
  • *Staða:** Í virkri nýtingu
  • *Veikar útgáfur:** Allar NG og MF útgáfur áður en vörn
  • *Lagfært í:** Uppfærsla útgefin 2026-08-28
  • *Tímabundin lausn:** Ekkert nefnt í heimildum
  • *Heimild:** [Rapid7 Research: PaperCut NG/MF Critical Zero-Day Exploited in the Wild](https://www.rapid7.com/blog/post/etr-papercut-ng-mf-critical-zero-day-exploited-in-the-wild)
  • *Citrix NetScaler ADC/Gateway Minnisskrun nýting** Einn áhrifaskil á Citrix NetScaler ADC og Gateway er í virkri nýtingu til að láta minnisskruna á vörn sem er stillt sem SAML auðkenningarþjónustu.
  • *CVE:** CVE-2026-3055 (CVSS: 9.3)
  • *Staða:** Í virkri nýtingu
  • *Veikar útgáfur:** Fjölmörg útgáfur áður en 14.1-66.59 og 13.1-62.23
  • *Lagfært í:** Uppfærðu í 14.1-66.59, 13.1-62.23, eða nýrra
  • *Tímabundin lausn:** Ekkert nefnt í heimildum
  • *Heimild:** [SecurityWeek: Recent Citrix NetScaler Vulnerability Exploited in the Wild](https://www.securityweek.com/?p=48907)
  • *ServiceNow AI Platform fjarkeyrsla kóða** Einn áhrifaskil á ServiceNow AI Platform er í virkri nýtingu með HTTP POST beðnir, sem leyfir óauðkenndum aðildum að keyra óvæntanlegan kóða.
  • *CVE:** CVE-2026-6875 (CVSS: 10.0)
  • *Staða:** Í virkri nýtingu
  • *Veikar útgáfur:** Fyrir Brazil EA og önnur fyrri útgáfur
  • *Lagfært í:** Uppfærðu út frá ServiceNow tilkynningu
  • *Tímabundin lausn:** Ekkert nefnt í heimildum
  • *Heimild:** [The Hacker News: Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Cod](https://thehackernews.com/2026/08/three-cvss-100-servicenow-flaws-could.html)
  • *Ubiquiti UniFi OS áhrifaskil með fjölmörgum veikleikum** Fjölmörg áhrifaskil á Ubiquiti UniFi vörum (Network Application, OS Server, Cloud Gateway Industrial) leyfa fjarkeyrslu kóða og réttindaaukning, með CVSS stig upp á 10.0.
  • *CVE:** CVE-2026-34910, CVE-2026-34909, CVE-2026-34908 (CVSS: Ekki tilgreint)
  • *Staða:** Í virkri nýtingu
  • *Veikar útgáfur:** Ekki tilgreint í heimildum — skoðið tilkynningu framleiðanda
  • *Lagfært í:** Uppfærðu í nýjasta UniFi OS útgáfur
  • *Tímabundin lausn:** Ekkert nefnt í heimildum
  • *Heimild:** [BSI Germany: [NEU] [hoch] Ubiquiti UnifiOS: Mehrere Schwachstellen](https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3028) ## 🔍 Þjónustu aðgerð
  • *ClickFix kampanj setur út Lumma Stealer með Windows Terminal.** Þetta er sýnilegt aðgerðarhugbúnaður sem vantar notendur að setja óþýða beðnir í Windows Terminal, sem hefur aðgang að aðgangi til að setja út Lumma Stealer. Aðgerðin notar kóðuð PowerShell beðnir og farsæla CAPTCHAs.
  • *Rússnesk APT notar Zimbra núll-daga veikleika fyrir spjall.** Stjórnendur grúpu "Laundry Bear" (TA488) notar núll-daga XSS veikleika (CVE-2025-66376) í Zimbra Collaboration Suite með netveiðar, sem leyfir útflutning gagna frá bandarískum og úkraínskum áhugamálum við að skoða netveiðar.
  • *Aukning í Microsoft Device Code Phishing.** Þjónustu aðildar notar Microsoft OAuth device code flow til að framhjá MFA og sækja aðgangslykilorð, sem leyfir aðgang að reikningi. Grúpur eins og ShinyHunters og EvilTokens eru tengdar þessum aðgerðum.
  • *FBI bannar Kína tengdum QTFY spjallneti.** FBI hefur bannað aðgangi á QTFY grúpu, sem áhrifði bandarískar stjórnarráðstefnur (t.d. NASA, DOE og Bandaríkisþingi) með sérstaklega tól (QScan, QTRouter) til að nýta veikleika eins og CVE-2019-11510. ## 📋 Uppfærslur og uppfærslur
  • *Microsoft Edge fjölmörg áhrifaskil.** Fjölmörg áhrifaskil (fjarkeyrsla kóða, upplýsingar útflutningur, og auðkenningarframhjáhlaup) á Microsoft Edge útgáfur áður en 146.0.7680.75. Einn (CVE-2026-3909) er merktur sem í virkri nýtingu. **Aðgerð:** Uppfærðu í nýjasta útgáfu á meðferð.
  • *Fjölmörg áhrifaskil í Redis.** Fjölmörg áhrifaskil (fjarkeyrsla kóða) á Redis útgáfur upp í 8.6.2, með notkun eftir minni og minnissöfnun. **Aðgerð:** Uppfærðu í Redis 8.6.3 eða nýrra.
  • *Fjölmörg áhrifaskil í Veeam Backup & Replication.** Fjölmörg áhrifaskil (t.d. CVE-2026-44963) leyfa fjarkeyrslu kóða og réttindaaukning í Veeam Backup & Replication útgáfur 12.x áður en 12.3.2.4465 og 13.x áður en 13.0.1.2067. **Aðgerð:** Uppfærðu á meðferð. ## Þjónustu dagsetningar 1. **Uppfærðu PaperCut og Citrix NetScaler á meðferð.** Þetta eru mest áhrifaskil, sem eru í virkri nýtingu. 2. **Skoðaðu og útfæra uppfærslur fyrir ServiceNow, Ubiquiti UniFi, Microsoft Edge, Redis og Veeam.** Þetta eru allar í virkri nýtingu eða með áhrifaskilum sem eru birt. 3. **Varnar notendur um ClickFix Windows Terminal netveiðar.** Þjónustu aðgerð á að bæta undirbúningi fyrir að setja beðnir frá óþýðum heimildum. 4. **Skoðaðu Microsoft OAuth device code aðgangi.** Mæla með að skoða óþýða aðgangi sem getur vísat til að sækja aðgangslykilorð. ## 🔗 Heimildir - [Rapid7 Research: PaperCut NG/MF Critical Zero-Day Exploited in the Wild](https://www.rapid7.com/blog/post/etr-papercut-ng-mf-critical-zero-day-exploited-in-the-wild) - [SecurityWeek: Recent Citrix NetScaler Vulnerability Exploited in the Wild](https://www.securityweek.com/?p=48907) - [The Hacker News: Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Cod](https://thehackernews.com/2026/08/three-cvss-100-servicenow-flaws-could.html) - [The Hacker News: FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organ](https://thehackernews.com/2026/08/fbi-disrupts-china-linked-qtfy.html) - [Microsoft Security Blog: TerminalFix campaign deploys a reverse tunnel through multistage intrusion](https://www.microsoft.com/en-us/security/blog/?p=149220)
Read Full Article →

## Executive Summary The threat landscape remains dominated by active exploitation of critical vulnerabilities across widely deployed enterprise software. **PaperCut NG/MF** and **Citrix NetScaler** are under immediate attack via newly disclosed zero-days, requiring urgent patching. State-sponsored activity is high, with the **FBI disrupting the China-linked QTFY espionage network** and Russian actors exploiting a **Zimbra zero-day**. Additionally, a novel social engineering campaign (**ClickFix**) is leveraging Windows Terminal to deploy malware, while a surge in **Microsoft Device Code Phishing** threatens MFA-protected accounts.

## ⚠️ Immediate Action Required

* **PaperCut NG/MF Zero-Day Authentication Bypass** A critical zero-day vulnerability in PaperCut NG/MF print management software is being actively exploited, allowing attackers to bypass authentication and execute remote code via crafted HTTP POST requests. * **CVE:** CVE-2023-27350 (CVSS: Not specified) * **Status:** Active exploitation detected * **Vulnerable:** All NG and MF versions prior to emergency patch * **Fixed:** Apply emergency patch released 2026-08-28 * **Workaround:** None mentioned in source * **Reference:** [Rapid7 Research: PaperCut NG/MF Critical Zero-Day Exploited in the Wild](https://www.rapid7.com/blog/post/etr-papercut-ng-mf-critical-zero-day-exploited-in-the-wild)

* **Citrix NetScaler ADC/Gateway Memory Leak Exploitation** A critical out-of-bounds read vulnerability in Citrix NetScaler ADC and Gateway is being actively exploited to leak sensitive memory data when configured as a SAML Identity Provider. * **CVE:** CVE-2026-3055 (CVSS: 9.3) * **Status:** Active exploitation detected * **Vulnerable:** Multiple versions prior to 14.1-66.59 and 13.1-62.23 * **Fixed:** Update to 14.1-66.59, 13.1-62.23, or later * **Workaround:** None mentioned in source * **Reference:** [SecurityWeek: Recent Citrix NetScaler Vulnerability Exploited in the Wild](https://www.securityweek.com/?p=48907)

* **ServiceNow AI Platform Remote Code Execution** A critical RCE vulnerability in the ServiceNow AI Platform is being exploited in the wild via HTTP POST requests, allowing unauthenticated attackers to execute arbitrary code. * **CVE:** CVE-2026-6875 (CVSS: 10.0) * **Status:** Active exploitation detected * **Vulnerable:** Pre-Brazil EA and other prior releases * **Fixed:** Apply patches from ServiceNow advisory * **Workaround:** None mentioned in source * **Reference:** [The Hacker News: Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Cod](https://thehackernews.com/2026/08/three-cvss-100-servicenow-flaws-could.html)

* **Ubiquiti UniFi OS Critical Vulnerability Chain** Multiple critical vulnerabilities in Ubiquiti UniFi products (Network Application, OS Server, Cloud Gateway Industrial) allow remote code execution and privilege escalation, with CVSS scores up to 10.0. * **CVE:** CVE-2026-34910, CVE-2026-34909, CVE-2026-34908 (CVSS: Not specified) * **Status:** Active exploitation detected * **Vulnerable:** Not specified in source — check vendor advisory * **Fixed:** Update to latest UniFi OS versions * **Workaround:** None mentioned in source * **Reference:** [BSI Germany: [NEU] [hoch] Ubiquiti UnifiOS: Mehrere Schwachstellen](https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3028)

## 🔍 Threat Activity

* **ClickFix Campaign Deploys Lumma Stealer via Windows Terminal.** A sophisticated social engineering campaign tricks users into pasting malicious commands into Windows Terminal, evading detection to deploy the Lumma Stealer credential thief. The attack uses encoded PowerShell commands and fake CAPTCHAs. * **Russian APT Exploits Zimbra Zero-Day for Espionage.** The state-sponsored group "Laundry Bear" (TA488) is exploiting a zero-day XSS vulnerability (CVE-2025-66376) in Zimbra Collaboration Suite via phishing emails, enabling data exfiltration from US and Ukrainian targets upon email preview. * **Microsoft Device Code Phishing Surge.** Threat actors are increasingly exploiting the Microsoft OAuth device code flow to bypass MFA and steal access tokens, enabling persistent account access. Groups like ShinyHunters and EvilTokens are linked to these campaigns. * **FBI Disrupts China-Linked QTFY Cyber Espionage Network.** The FBI has taken down infrastructure used by the QTFY group, which targeted U.S. federal agencies (including NASA, DOE, and the U.S. Senate) using custom tools (QScan, QTRouter) to exploit vulnerabilities like CVE-2019-11510.

## 📋 Patches & Updates

* **Microsoft Edge Multiple Critical Vulnerabilities.** Multiple critical RCE, information disclosure, and policy bypass flaws affect Edge versions prior to 146.0.7680.75. One (CVE-2026-3909) is noted as actively exploited. **Action:** Update to the latest version immediately. * **Multiple Critical Redis Vulnerabilities.** Several critical RCE vulnerabilities (e.g., CVE-2026-23479, CVE-2026-25243) affect Redis versions up to 8.6.2, involving use-after-free and memory handling issues. **Action:** Upgrade to Redis 8.6.3 or later. * **Veeam Backup & Replication Critical RCE Flaws.** Multiple critical vulnerabilities (including CVE-2026-44963) allow remote code execution and privilege escalation in Veeam Backup & Replication versions 12.x prior to 12.3.2.4465 and 13.x prior to 13.0.1.2067. **Action:** Apply patches immediately.

## Today's Priorities 1. **Patch PaperCut and Citrix NetScaler immediately.** These are the most urgent, actively exploited zero-days. 2. **Review and apply patches for ServiceNow, Ubiquiti UniFi, Microsoft Edge, Redis, and Veeam.** These are all under active exploitation or have critical public vulnerabilities. 3. **Alert users to the ClickFix Windows Terminal phishing campaign.** Reinforce training against pasting commands from untrusted sources. 4. **Audit Microsoft OAuth device code authorizations.** Monitor for suspicious device authorizations that could indicate token theft attempts.

## 🔗 References

  • [Rapid7 Research: PaperCut NG/MF Critical Zero-Day Exploited in the Wild](https://www.rapid7.com/blog/post/etr-papercut-ng-mf-critical-zero-day-exploited-in-the-wild)
  • [SecurityWeek: Recent Citrix NetScaler Vulnerability Exploited in the Wild](https://www.securityweek.com/?p=48907)
  • [The Hacker News: Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Cod](https://thehackernews.com/2026/08/three-cvss-100-servicenow-flaws-could.html)
  • [The Hacker News: FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organ](https://thehackernews.com/2026/08/fbi-disrupts-china-linked-qtfy.html)
  • [Microsoft Security Blog: TerminalFix campaign deploys a reverse tunnel through multistage intrusion](https://www.microsoft.com/en-us/security/blog/?p=149220)

Share this article