Compiled from 52 monitored sources · 423 articles reviewed
Today’s Briefing
PaperCut Software disclosed active exploitation of an unnamed zero-day affecting its NG and MF print management products, with emergency patches released but no CVE assigned or technical detail published yet. Microsoft Threat Intelligence separately documented TerminalFix, a ClickFix campaign using fake CAPTCHA prompts and DLL sideloading to deploy a reverse tunnel. Four critical Apache Tomcat CVEs appeared on the watchlist today.CVE-2026-68525, CVE-2026-65905, CVE-2026-65637, and CVE-2026-65182.covering FORM authentication bypass, DIGEST authenticator replay, incomplete input validation remediation, and security constraint path ordering flaws respectively.
Top Stories
- TerminalFix campaign deploys a reverse tunnel through multistage intrusion
- PaperCut Zero-Day Under Active Attack: Emergency Patch Released
- PaperCut NG/MF Critical Zero-Day Exploited in the Wild
Full brief available to subscribers
The complete operator brief — action items with patch deadlines, the vulnerability appendix and named actor activity — goes out by email each morning. Subscribe free to receive it.