
Hello all,
Three headline news items merit immediate attention if you have any of the products under your care; more on that in a moment. There is a lot of good news about takedowns and arrests, and unfortunately some serious news about an exfiltrating ransomware attack on the US Department of Alcohol Tabacco and Firearms (ATF). We also list a goodly number of vulnerabilities, ransomware and leak reports, and AI related news links on our website.
This email and video commentary is from the RedDotSecurity.news website that contains a plethora of links to other items, not mentioned here, that are worth skimming to see if they interest you or pertain to your particular environment or of those you support. There is a lot more than what is provided in these opening comments. Now, on to the headline news.
Headline NEWS:
- PaperCut warns of NG, MG flaw exploited in zero day attacks is a news item that exploded into view late in the week on Thursday, and again on Friday when a second emergency patch was released by the vendor. Researchers at Huntress and watchTowr reproduced the full exploit chain, observed real-world exploitation in customer environments, and identified additional bypasses. PaperCut urges all customers to install Emergency Patch Release 2 on Site Servers and secondary/print servers, even if they already applied the first patch, and to restrict access to the web interface to trusted IPs.
- ServiceNow warns of three max severity security vulnerabilities. If unpatched the defects can enable privilege escalation, SQL injection, and arbitrary code injection. To make matters significantly worse, the flaws don’t require authentication to exploit. Additionally, the vendor announced another vulnerability on Thursday, this time it is a sandbox escape that could enable a threat actor that obtained basic privileges to escalate to remote code execution (RCE). Cloud hosted instances have been patched by the vendor, self-hosted clients are urged to patch to the latest versions immediately.
- Ubiquiti patches three max severity security vulnerabilities. Unfortunately, these defects can be exploited remotely, and without authentication. That’s about as bad as it gets. If that wasn’t enough, the next day, Ubiquiti released patches for 18 additional security vulnerabilities, spanning quite a few products. The advisory covers almost every major UniFi product line, including: UniFi OS platform devices (Dream Machines, Gateways, NVRs, NAS, Cloud Keys, etc.), UniFi Protect, UniFi Network, UniFi Access, UniFi Connect, UID Enterprise Agent, UniFi Talk, UniFi Enterprise AV Bridge, and UniFi Protect AI Key. There is no mention of active exploitation yet, so patch quickly, starting with anything that is publicly facing.
In Ransomware, Malware, and Vulnerabilities News:
- Navy orders personnel, families to remove personal details from social media for security. While it has been the practice of military personnel and their families to routinely limit what they post in social media, the directive from the Secretary of the Navy (SECNAV) is quite specific in how social media should be configured, what information should not be shared, and what to do and how to respond when something seems amiss. Citing that there have been, “Direct threats and harassment targeting our personnel and their families via social media and other online platforms, often including doxing (publication of personal information).” and a list of other enhanced warfare tactics, the Naval Criminal Investigative Service (NCIS) has implemented EPIC VIGILANCE, designed to limit information sharing and exposure, and reporting of anything suspicious.
In Other News Events of Note and Interest:
- Simon Weckert creates Digital Camouflage to avoid AI surveillance. I found an interesting article for the paranoid among us, you know who you are, that should bring you a bit of a smile. Apparently, this Simon dude researched and figured out a print pattern that when applied to clothing can confuse an AI so that it doesn’t recognize that there’s a person on camera. Side by side examples of people wearing his rather loud Hawaiian style shirt, next to ordinarily clothed people shows that the AI doesn’t recognize the one wearing the AI camo shirt. Cool! I know you want one, here’s the link.
Musings
In the southeast US we have the ever-imminent threat of hurricanes, generally from June 1 through November 30 during Atlantic hurricane season. I recall in 2004 when Florida had four significant hurricanes hit the state within six weeks. I attempted to purchase a generator after the first one and discovered that they were sold out. And it stayed that way for a long time. Knowing that it was just a matter of “when” and not “If” we would experience another event; after the season ended, I purchased a generator, and put the box in my garage, where it remained for the next 20 years. When my area was affected by hurricanes Debby, Helen, and Milton in 2024, thankfully, my home didn’t sustain any damage and the generator (still in the original box) was well preserved, in a dry place, so, I was able to assemble the generator and keep the power on. Had I not prepared in advance, all those years ago, I would have lost a lot of food, slept uncomfortably, and not had hot coffee. As mentioned, with hurricanes you prepare for the “when”, not the “if”. That applies to cybersecurity as well. Prepare before things start to fly around chaotically.

Keep the shields up!
Viscount Jan Broucinek
Red Dot Security News
Headline NEWS
- PaperCut warns of NG, MF flaw exploited in zero-day attacks
- PaperCut releases second emergency patch for exploited flaws
- ServiceNow warns of three max severity security vulnerabilities
- Ubiquiti patches three max severity security vulnerabilities
Ransomware, Malware, and Vulnerabilities News
- Good News, Government News, and Interesting
- NIST taps Electrosoft to advance post-quantum digital identity
- The White House says it no longer considers data storage and data centers ‘critical’ technology
- Massive DDoS attack disrupts Norway’s government digital services
- Pro-Russian hacker group claims cyberattack on Norwegian public services
- GSA, Treasury kick off post-quantum initiatives to protect against cyber threats
- More than 100 water systems were hit in July cyberattacks
- S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches
- Police arrests dozens of suspects in global cybercrime crackdown
- INTERPOL Operation Jackal IV Arrests 58, Identifies 263 in Global Cyber Fraud Crackdown
- Australian cops cuff alleged TeamPCP masterminds
- Vulnerabilities and Exploits
- CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs
- CISA slaps its tightest three-day patching deadline on perfect-10 Oracle flaw
- Fed, NASA, DOJ targeted by Chinese state-sponsored hackers
- US revises statements suggesting Chinese hackers attacked agencies
- FBI disrupts proxy network enabling Chinese espionage operations
- Inaudible sounds used to fingerprint browsers catch AliExpress red-handed
- The Vulnerability Gap: Why Discovery Is Outrunning Repair
- The patch window is collapsing: Why security needs a new control plane
- Exploited Zimbra Flaw Highlights Shrinking Window to Patch
- Unpatched Calix flaw lets hackers bypass NAT to expose internal devices
- Critical Keycloak Password Reset Flaw Could Let Unauthenticated Attackers Take Over Any Account
- 91 Vulnerabilities Patched in Spring Application Framework
- Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access
- Multiple TP-Link Archer Vulnerabilities Enable Command Injection Attacks
- Apple Quietly Fixes iCloud Private Relay Vulnerability in iOS 26.6.1
- The Iran war is bringing cyberwarfare into critical infrastructure
- Critical Metal Gear Online 3 vulnerability enables RCE
- Multiple OpenSSL Flaws Let Remote Attackers Crash Servers and Corrupt Heap Memory
- Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code
- Hackers target Microsoft SharePoint RCE chain with PoC exploit
- New GPUThor attack defeats NVIDIA ECC protection for root access
- Critical Avada WordPress theme flaw enables zero-click RCE
- Chrome just patched 320+ security flaws, and paid $25K for one of them
- Chinese Routers Sold Worldwide Contain Backdoors
- Australia Warns of Active Exploitation of Critical TeamCity Server Flaw
- js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE
- JetBrains told everyone to patch. It didn’t patch itself.
- Phishing, Malware, and Similar
- Your Open Source Model Could Have a Hidden Time-Release Backdoor
- Fake Minecraft Clients Deliver WeedHack Malware Despite Takedown
- Crooks push Mac malware through fake OpenAI Codex ads
- Hackers Place Fake Codex Download Above Legitimate OpenAI Result to Infect Mac Users
- Inside the Myanmar scam compounds where trafficked workers target Indian Americans
- 24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages
- You don’t want this Sleepwalker backdoor on your Windows machine
- Slovakia finds Russian backdoor in traffic speed cameras
- Hackers now exploit critical Gitea flaw in code injection attacks
- Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows
- Dark Caracal Adds New Malware to Cyber Espionage Arsenal
- APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations
- ‘NovaCookies’ Kit Steals Microsoft 365 Sessions for $320 a Month
- Breaches, Leaks, and Ransomware
- ATF responds to ‘major’ cybersecurity incident after ransomware gang’s claims
- US government alcohol and firearms agency ATF declares ‘major incident’ after ransomware gang claims cyberattack
- South Korean startup platform breach exposes key management failures
- ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body
- Navy orders personnel, families to remove personal details from social media for security
- Alation confirms cyberattack after reporting system incident
- Private equity firm Apollo confirms data breach amid hacking wave targeting financial giants
- LACMA data breach last year exposed social security and medical data
- ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited
- Bad Connection: Uncovering Global Telecom Exploitation by Covert Surveillance Actors
- Carhartt data breach affects 12.9M, half of what ShinyHunters claimed
- Troy Hunt: A Cautionary Tale About Data Breach Claims, Verification and Carhartt
- Employee benefits platform Paylogix says hackers stole financial and health data
- Sensitive Information Exposed in Nutex Health Data Breach
- Medical device maker Boston Scientific says a cyberattack is causing a ‘global disruption’ to its operations
- Three UK airports hit by cyber-attack with data of 8.7m customers accessed
Other News Events of Note and Interest
- Cool Tool: LibreOffice 26.8 brings professional typography, deeper support for the world’s writing systems, and no artificial intelligence
- Amazon’s Toaster-Shaped Robotaxis Are Hitting the Road
- Tesla confirms Cybercab launch coming next week
- A Sloppy Interface Is a Security Liability
- Lenovo finally acknowledges Legion Go BIOS bricking issues and confirms affected devices should be repaired “free of charge”
- Windows NT 4 went on sale 30 years ago
- Netflix, YouTube and Amazon Want You to Watch Everything From One App: Theirs
- WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android
- Meta to Pay Up to $17.1 Billion in Landmark Settlement Over Social Media Addiction Claims
- What Meta’s settlement may mean for Big Tech
- Buried in Meta’s $18B settlement is a legal pass on kids’ data
- Salesforce, Anthropic expand partnership amid ‘SaaSpocalypse’ concerns
- Ads have landed in Apple Maps, and they are as bad as expected
- AI, LLM’s, Robots, and Skynet
- OpenAI, Anthropic issue dire cyber threat warning, we’re running out of time
- Bill Gates wants to see a robot tax and ‘Human Reserved’ jobs to mitigate harms from AI
- Bill Gates is deeply worried about AI, and he’s no longer staying quiet
- Anthropic’s new hardware standard lets AI agents control the physical world
- Hugging Face is selling a cute $399 open source duck robot, Microduck
- We urgently need a coherent national AI cybersecurity policy
- Chinese humanoid robots break human records at Beijing’s robot games
- Robots can outrun humans, but can they plug in a cable?
- Bringing the cybersecurity capabilities of Claude Mythos 5 to more defenders
- ChatGPT for iPhone now lets users grab recent photos with a long press
- Data centers become “killer application” for new power transformer tech
- Hidden Prompts Trick AI Into False Email Summaries
- Adobe wants Firefly to handle the entire soundtrack for your videos
- Apple’s new desktop computers are designed specifically for local AI development
- Linux Foundation to Govern TRACE, an Open Standard for AI Runtime Attestation
- Simon Weckert creates Digital Camouflage to avoid AI surveillance
- AI agents meant to replace Meta workers made “large-scale, disruptive actions”
- Are AI Datacenter Bans Going Too Far?
- Microsoft
- Windows 11 26H2 is weeks away, and Microsoft just revealed everything about it
- Windows 11 26H2 Goes Into Release Preview Channel
- Microsoft: August updates break printing, PDF export in WPF apps
- OneDrive for macOS is about to get a whole lot faster
- Remote Help on Windows: Unattended Support with Remote Sign-In Is Here
- Microsoft is blocking the problem to fix Windows 11 KB5121003 restarts, crashes
- Microsoft finally brings another long awaited Windows troubleshooting feature
- Microsoft releases Windows 11 KB5120998 with long list of improvements and fixes
- “We’re aware,” Microsoft on Windows 11 KB5120998 breaking the mouse cursor
- Windows 11 is warning “Virus protection is off,” Microsoft confirms it’s false, but verify if Defender is actually enabled
