
Threat Level: CRITICAL12 stories · 5 sources · ~10 min read
Today’s 3 Big Things
- Immediately prioritize patch deployment and threat hunting for actively exploited zero-days in print (PaperCut), VoIP (Switchvox), and DevOps (JFrog Artifactory) infrastructure.
- Conduct comprehensive risk assessments for onboarding and fraud processes reliant on drivers license image verification due to mass data exposure now available to criminals.
- Proactively review and remediate open-source software dependencies, browser fleets, and ICS controller vulnerabilities to reduce the window of exploitation for both commodity and targeted attacks.
Coverage: Last 24 hours
Today’s Highlights
Critical infrastructure, developer supply chain threats, and large-scale identity exposure dominated today’s operational risk landscape. Key themes include sensitive personal data breach exposure, critical zero-day exploitation targeting VoIP, DevOps, and ICS environments, active open-source and payment supply-chain manipulation, and urgent vulnerabilities in browser and core network utilities. Defensive readiness and rapid patch cycles are essential to mitigate cascading impacts across sectors.
Defensive Actions
- Deploy PaperCut Emergency Patch Release 3 across all NG/MF installations immediately, scanning for compromise and restricting external exposure.
- Apply vendor fixes for CVE-2026-9586 on all Sangoma Switchvox systems and monitor for evidence of webshells or abuse.
- Update all JFrog Artifactory servers for CVE-2026-82329, review admin tokens, and rotate credentials used since the disclosure.
- Patch GeoNetwork backends to 4.4.12/4.2.17 and remove non-essential public-facing portals.
- Push Chrome 152.0.7977.75 or later to all endpoints, especially those in high-risk environments, and review for sandbox escapes.
- Instruct onboarding and fraud teams to detect attempts using driver’s license images, especially those flagged as duplicates.
- Purge identified malicious Composer packages and notify affected downstream users, monitoring for iOS spyware campaigns.
- Segment industrial control networks and apply patches for Nucleus FTP (CVE-2021-31886), especially regarding WAGO PLC exposure.
- Inventory internal tools and appliances bundling curl/libpsl and update to 8.22.0 to ensure session boundaries are maintained.
- Enhance payment monitoring and anomaly detection in Brazil-focused financial environments against Breeze Comet tactics.
Table of Contents
- FBI Probes Service Selling 153M+ Drivers Licenses
- Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another
- Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials
- Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure
- Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems
- 13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds
- PaperCut publishes Emergency Patch Release 3 amid confirmed active exploitation of NG/MF vulnerability
- CVE‑2026‑84354: High‑severity Chrome FileSystem authorization flaw enables remote code execution
- curl fixes cookie‑PSL boundary check flaw; curl 8.22.0 released with patch for CVE‑2026‑82209
Top Stories
FBI Probes Service Selling 153M+ Drivers Licenses
Source: Krebs on Security | Risk: CRITICAL | Impacted: Identity verification providers, Financial institutions, Healthcare onboarding portals, Government service platforms
Summary: A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are available for purchase on this service, it appears to be siphoning images collected by a widely-used identity verification company based in.
Why it matters: This volume of leaked government-issued IDs creates an enduring resource for criminals compromising onboarding flows, perpetrating fraud, and bypassing identity controls across sectors.
Practitioner Perspective
Any service or business using third-party identity verification now faces increased risk of customer impersonation and fraudulent account creation, especially where license scans are a factor in trust decisions. The scale exposes all sectors to persistent synthetic identity and account takeover risks. Expect an uptick in social engineering and credential stuffing as threat actors weaponize this dataset, particularly targeting banks, fintech, healthcare, and government portals. If your organization relies on ID-based verification, assume increased false positives and consider out-of-band confirmation or behavioral analytics. Attackers no longer need to phish for these images, they are commoditized.
Recommended Actions
- Alert fraud operations and onboarding teams to the immediate risk of drivers license image replay, review recent onboarding flagged for duplicate licenses
- Harden secondary authentication and KYC for high-risk account creation journeys, especially where driver’s license images are accepted
Emerging Signals
Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems
Source: The Hacker News | Risk: HIGH | Impacted: Brazilian fintechs, Payment processors operating in Brazil, Retail e-commerce accepting BR payment standards
Summary: Brazilian financial services, retail, and e-commerce organizations have become the target of a financially motivated threat actor dubbed Breeze Comet (formerly UNC5669) since 2024. Google Threat Intelligence Group (GTIG) and Mandiant teams described the threat actor as “specializing in manipulating payment systems and banking software in Brazil to conduct fraudulent transfers.” The adversary.
Why it matters: Targeted manipulation of Brazilian payment and banking systems means regional financial organizations face direct monetary losses and reputational harm from a specialized, persistent actor.
Practitioner Perspective
Breeze Comet demonstrates that regionally-focused threat actors can maintain deep knowledge of local payment protocols and execute large-scale fraud undetected. If you operate in Brazil’s payment ecosystem, assume attackers are testing both traditional fraud vectors and novel manipulation of payment rails or core banking engines. Visibility into transactional anomalies and advanced behavioral analytics are now table stakes. Collaboration with peer banks and regulatory agencies is essential to track evolving tactics. Don’t underestimate the sophistication of threat groups targeting domestic systems, local knowledge is a force multiplier for attackers.
Recommended Actions
- Analyze recent payment flows for anomalies consistent with fraudulent transfers as seen in Breeze Comet operations
- Update fraud detection systems to prioritize manipulation at the protocol and application layers
13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds
Source: The Hacker News | Risk: HIGH | Impacted: PHP development teams (Vietnamese media), Packagist/Composer maintainers, iPhone users (Vietnam, crypto holders)
Summary: Cybersecurity researchers have identified a set of 13 malicious Composer theme packages on Packagist that are designed to inject JavaScript into Vietnamese movie and comic streaming sites that install those libraries and initiate the deployment of spyware aimed at unpatched iOS devices. “The injected code runs two operations against a site’s visitors: a mobile ad-fraud and gambling-redirect.
Why it matters: Exploiting open-source PHP dependencies allows threat actors to infect streaming site visitors with spyware targeting unpatched iOS, extending supply-chain risk to end users’ crypto assets and privacy.
Practitioner Perspective
This incident exemplifies the risk that tainted Composer packages on Packagist pose to web applications and, by extension, their unwitting audiences. Developers maintaining Vietnamese-language media and comic platforms are the initial exposure point, but users of unpatched iPhones become downstream targets for crypto wallet theft and surveillance. Prioritize removal and replacement of the listed Composer packages and treat all recent site visitors as potentially exposed. Security teams must educate developers about vetting open-source dependencies, given the continuous targeting of the software supply chain.
Recommended Actions
- Purge all 13 identified malicious Composer packages from production and review dependency trees for secondary infection
- Notify downstream site operators and visitors about the spyware risk if their site installed affected packages
Exploits & CVEs
Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another
Source: The Hacker News | Risk: HIGH | Impacted: WAGO PLC fleets, ICS asset owners using Nucleus FTP, Critical manufacturing and energy SCADA
Summary: Forescout Research – Vedere Labs said it used Anthropic’s Claude to port a working pre-authentication remote code execution (RCE) exploit from one WAGO programmable logic controller (PLC) to another, executing attacker-supplied ARM shellcode on live hardware. The exploit targets CVE-2021-31886, a stack-based buffer overflow in the Nucleus FTP server’s handling of the USER command.
Why it matters: Adversaries can now use generative AI to efficiently customize exploits for closely related devices, accelerating ICS zero-day commoditization.
Practitioner Perspective
Industrial operators running WAGO PLCs, or any ICS powered by Nucleus FTP (CVE-2021-31886), face an evolution in the threat model: offensive AI tools can lower the cost and technical barrier for complex pre-auth RCE attacks. Small changes in ICS architectures are no longer a reliable defense when AI expedites exploit porting. This scenario raises the bar for what defenders must monitor: rapid exploit proliferation, not just exploit discovery, will drive industrial compromise attempts. ICS security teams must re-evaluate how quickly they can respond to variant exploit development and patch deployment.
Recommended Actions
- Patch or segment PLCs vulnerable to CVE-2021-31886, especially those using Nucleus FTP for remote access
- Review firewall and remote access policies for ICS devices, block unnecessary FTP/S protocols
Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials
Source: The Hacker News | Risk: CRITICAL | Impacted: Sangoma Switchvox SMB deployments, Enterprise VoIP administrators, Corporate telephony infrastructure
Summary: Threat actors are exploiting a severe security vulnerability in Sangoma Switchvox, an enterprise VoIP platform, that could allow unauthenticated remote code execution. The vulnerability in question is CVE-2026-9586 (CVSS score: 9.3), a critical unauthenticated SQL injection vulnerability in Sangoma Switchvox SMB Edition 8.3 (104997) that can allow attackers to remotely execute arbitrary code as.
Why it matters: Active exploitation of an unauthenticated, critical SQL injection flaw in enterprise VoIP puts corporate voice infrastructure at risk for covert, persistent code execution and data breach.
Practitioner Perspective
Sangoma Switchvox (especially SMB Edition 8.3 build 104997) should be assumed compromised if not yet patched for CVE-2026-9586. Attackers can remotely deploy reverse shells and execute arbitrary code with no credentials, which means VoIP infrastructure could be subverted for eavesdropping, internal pivoting, or data exfiltration. Ransomware, toll fraud, and conversation capture are realistic threats. The pace of exploitation suggests defenders cannot wait for routine patch cycles: immediate response and forensic review are mandatory. Remove VoIP systems from internet exposure where possible and validate their integrity now.
Recommended Actions
- Apply the vendor fix for CVE-2026-9586 to all affected Switchvox systems immediately
- Scan for webshells or evidence of reverse shell sessions on Switchvox servers
Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure
Source: The Hacker News | Risk: CRITICAL | Impacted: DevOps teams using JFrog Artifactory, Software engineering groups, Enterprises with automated CI/CD pipelines
Summary: Threat actors are exploiting a newly patched critical security flaw impacting JFrog Artifactory merely days after public disclosure, according to watchTowr. The vulnerability in question is CVE-2026-82329 (CVSS score: 9.8), a case of authentication bypass that could lead to administrative access in Artifactory. “JFrog Artifactory contains an authentication weakness that, under default.
Why it matters: Compromise of developer artifact repositories through authentication bypass lets attackers poison build pipelines or steal source at scale within days of disclosure.
Practitioner Perspective
JFrog Artifactory instances vulnerable to CVE-2026-82329 are an immediate target due to public proof-of-concept availability and active post-disclosure exploitation. Malicious actors obtaining admin access can seed repositories with trojans or exfiltrate sensitive intellectual property uncontrolled. Security teams must treat unpatched Artifactory environments as suspect, especially in high-velocity or continuous deployment organizations. For environments using default configurations, assume exposure and inspect for unauthorized admin token issuance.
Recommended Actions
- Apply the patch for CVE-2026-82329 to all JFrog Artifactory servers as a top external priority
- Review admin token issuance logs post-disclosure for anomalous activity
What We’re Watching
- Active exploitation of CVE-2026-82329 (JFrog Artifactory) and CVE-2026-9586 (Sangoma Switchvox) is ongoing; monitor for post-patch adversary persistence.
- Emergency patch rollout for PaperCut NG/MF installations is required in response to in-the-wild attacks against internet-accessible print servers.
- Potential expansion of Breeze Comet tactics to other Latin America-based payment or e-commerce systems should be watched closely.
- New malicious open-source PHP packages targeting media streaming sites and iOS users are expected; monitor for new supply-chain insertions on Packagist.
- Security teams should prepare for further sandbox bypass exploit attempts against Chrome endpoints, focusing on FileSystem API abuse.
Categories: Cybersecurity Blog, Cybersecurity News
Leave a Reply