August 29, 2026

Header image for the Red Dot Weekly Cyber Security News https://reddotsecurity.news

Hello all,

Three headline news items merit immediate attention if you have any of the products under your care; more on that in a moment. There is a lot of good news about takedowns and arrests, and unfortunately some serious news about an exfiltrating ransomware attack on the US Department of Alcohol Tabacco and Firearms (ATF). We also list a goodly number of vulnerabilities, ransomware and leak reports, and AI related news links on our website.

This email and video commentary is from the RedDotSecurity.news website that contains a plethora of links to other items, not mentioned here, that are worth skimming to see if they interest you or pertain to your particular environment or of those you support. There is a lot more than what is provided in these opening comments. Now, on to the headline news.

Headline NEWS:

  • PaperCut warns of NG, MG flaw exploited in zero day attacks is a news item that exploded into view late in the week on Thursday, and again on Friday when a second emergency patch was released by the vendor. Researchers at Huntress and watchTowr reproduced the full exploit chain, observed real-world exploitation in customer environments, and identified additional bypasses. PaperCut urges all customers to install Emergency Patch Release 2 on Site Servers and secondary/print servers, even if they already applied the first patch, and to restrict access to the web interface to trusted IPs.
  • ServiceNow warns of three max severity security vulnerabilities. If unpatched the defects can enable privilege escalation, SQL injection, and arbitrary code injection. To make matters significantly worse, the flaws don’t require authentication to exploit. Additionally, the vendor announced another vulnerability on Thursday, this time it is a sandbox escape that could enable a threat actor that obtained basic privileges to escalate to remote code execution (RCE). Cloud hosted instances have been patched by the vendor, self-hosted clients are urged to patch to the latest versions immediately.
  • Ubiquiti patches three max severity security vulnerabilities. Unfortunately, these defects can be exploited remotely, and without authentication. That’s about as bad as it gets. If that wasn’t enough, the next day, Ubiquiti released patches for 18 additional security vulnerabilities, spanning quite a few products. The advisory covers almost every major UniFi product line, including: UniFi OS platform devices (Dream Machines, Gateways, NVRs, NAS, Cloud Keys, etc.), UniFi Protect, UniFi Network, UniFi Access, UniFi Connect, UID Enterprise Agent, UniFi Talk, UniFi Enterprise AV Bridge, and UniFi Protect AI Key. There is no mention of active exploitation yet, so patch quickly, starting with anything that is publicly facing.

In Ransomware, Malware, and Vulnerabilities News:

  • Navy orders personnel, families to remove personal details from social media for security. While it has been the practice of military personnel and their families to routinely limit what they post in social media, the directive from the Secretary of the Navy (SECNAV) is quite specific in how social media should be configured, what information should not be shared, and what to do and how to respond when something seems amiss. Citing that there have been, “Direct threats and harassment targeting our personnel and their families via social media and other online platforms, often including doxing (publication of personal information).” and a list of other enhanced warfare tactics, the Naval Criminal Investigative Service (NCIS) has implemented EPIC VIGILANCE, designed to limit information sharing and exposure, and reporting of anything suspicious.

In Other News Events of Note and Interest:

  • Simon Weckert creates Digital Camouflage to avoid AI surveillance. I found an interesting article for the paranoid among us, you know who you are, that should bring you a bit of a smile. Apparently, this Simon dude researched and figured out a print pattern that when applied to clothing can confuse an AI so that it doesn’t recognize that there’s a person on camera. Side by side examples of people wearing his rather loud Hawaiian style shirt, next to ordinarily clothed people shows that the AI doesn’t recognize the one wearing the AI camo shirt. Cool! I know you want one, here’s the link.

Musings

In the southeast US we have the ever-imminent threat of hurricanes, generally from June 1 through November 30 during Atlantic hurricane season. I recall in 2004 when Florida had four significant hurricanes hit the state within six weeks. I attempted to purchase a generator after the first one and discovered that they were sold out. And it stayed that way for a long time. Knowing that it was just a matter of “when” and not “If” we would experience another event; after the season ended, I purchased a generator, and put the box in my garage, where it remained for the next 20 years. When my area was affected by hurricanes Debby, Helen, and Milton in 2024, thankfully, my home didn’t sustain any damage and the generator (still in the original box) was well preserved, in a dry place, so, I was able to assemble the generator and keep the power on. Had I not prepared in advance, all those years ago, I would have lost a lot of food, slept uncomfortably, and not had hot coffee. As mentioned, with hurricanes you prepare for the “when”, not the “if”. That applies to cybersecurity as well. Prepare before things start to fly around chaotically.

Visc. Jan Broucinek

Keep the shields up!

Viscount Jan Broucinek
Red Dot Security News

Headline NEWS

Ransomware, Malware, and Vulnerabilities News

Other News Events of Note and Interest
Share this with:

Leave a Reply

Your email address will not be published. Required fields are marked *