Cyberattacks

PaperCut issues emergency patches as threat actors target chained vulnerabilities
PaperCut released an emergency patch on Friday to fix critical vulnerabilities in its print management software. The company confirmed that multiple customers were targeted in directed attacks and collaborated with security researchers from Huntress and watchTowr in response. The vulnerabilities involve improper access control and insecure dynamic class loading, which can be chained to achieve unauthorized full compromise.

State-linked actor targets Cisco routers for espionage
Sygnia released a report on Sunday disclosing that a sophisticated hacker group linked to our country (codenamed Fire Ant) is exploiting routers running the Cisco IOS XR operating system to conduct espionage, targeting high-value networks and critical infrastructure. The group previously gained widespread attention for abusing VMware environments in 2025. The investigation found that attackers stole credentials by manipulating the TACACS authentication process and deployed BridgeAgent, a backdoor tool disguised as Zabbix, along with TacTap, a credential-stealing tool. Sygnia recommends that security teams adopt measures such as restricting privileged access, monitoring abnormal tunnel interfaces, and centralizing authentication to defend against these threats.

Salesforce gave every org the same free scanner. Attackers already know what it misses.

Civil-society initiative will pay cybersecurity vendors to protect rural water systems
At DEF CON, the Franklin project announced it will pay cybersecurity firms to offer free monitoring and protection to water utilities serving fewer than 10,000 people, addressing digital vulnerabilities highlighted by recent Iran-linked attacks. Five MDR providers will participate, sharing threat intelligence through a new Water Watch Center run by the National Rural Water Association.