The threat group it tracks as UTA0565 exploited the vulnerabilities in Chrome and Microsoft between Sept. 3 and 4 before the defects were disclosed or patched, researchers said.
The timing of the malicious activity mirrors other spikes threat hunters observed and attributed to multiple Chinese espionage threat groups. Yet, Volexity noted UTA0565βs campaigns differed from those attacks by using multiple fake websites to deceive victims.
Volexity shared phishing emails UTA0565 sent to Asian government entities urging them to publicly support imprisoned Hong Kong activist Chow Hang-tung. The group spoofed domains impersonating the Center for American Progress and China Digital Times in other phishing emails.
While UTA0565 showcased a variance in tactics, it used the same components researchers observed in previous instances of the exploit kit across multiple Chinese threat groups.
βThis seemingly widespread adoption across multiple threat actors suggests a coordinated effort within the Chinese computer network exploitation community, where the core kit was likely shared, customized, and weaponized by multiple groups,β Volexity wrote in the blog post. βThe activity reported so far reflects only two organizationsβ observations; the full scope and impact are likely far broader.β
Proofpoint, which previously observed multiple state-aligned threat groups chaining the vulnerabilities together in attacks since last August, said a limited group of organizations were exposed to all three vulnerabilities in a short window.Β
Proofpoint previously attributed attacks involving the zero-days to APT31, UNK_LateNight, UNK_DoubleCheck and UNK_QuietRacket. At the time it warned that attackers of other origins and motivations could strike soon as well.
Volexity said UTA0565 used a payload from a previously undocumented malware family it tracks as βCLEANGULP.β Researchers also found several domains likely used by UTA0565 in similar campaigns targeting media organizations, halal restaurant search websites and corporate training organizations.Β
βUTA0565βs use of the zero-day vulnerabilities shows technical and operational improvements over other campaigns observed by Volexity, both in the mechanics of the exploitation and the presentation to end users,β researchers wrote. βUsing real content from legitimate websites as decoy material continues to be an effective way to reduce user suspicion.β
Cisco disclosed its second actively exploited zero-day vulnerability in as many days, presenting its customers with back-to-back threats to address in unrelated products.
The latest zero-day β CVE-2026-76460 β has a maximum-severity rating and was exploited before Cisco disclosed and patched the vulnerability Wednesday. The defect in an API of Cisco Identity Services Engine (ISE) allows a remote attacker to bypass authentication and gain full control of the affected device.
βISE devices enforce network access policy, so root access on the appliance lets an attacker modify that policy, extract stored credentials, delete logs, and move laterally into every network segment ISE controls,β Landon Rice, senior exploit developer at VulnCheck, told CyberScoop.
Cisco did not say how many organizations have been compromised thus far, but reported it found the vulnerability during a technical support case.Β
βCisco is aware of active exploitation of this vulnerability. We strongly recommend customers upgrade to available fixed software and follow guidance in the advisory,β a Cisco spokesperson said in a statement.
The Cybersecurity and Infrastructure Security Agency added the zero-day to its known exploited vulnerabilities catalog shortly after Ciscoβs disclosure.Β
Researchers havenβt attributed attacks involving CVE-2026-76460 to any known group or threat actor, but Rice noted Cisco ISE vulnerabilities are a recurring target.Β
Multiple vulnerabilities affecting the Cisco product have been exploited since June 2025, including CVE-2025-20337 and CVE-2025-20281. The latest zero-day vulnerability and the pair of defects disclosed in the summer of 2025 were all rated critical with the highest rating of 10.Β
Cisco didnβt say when the first instance of CVE-2026-76460 exploitation occurred, but the disclosure came just two days after the vendor disclosed CVE-2026-76461, an actively exploited zero-day vulnerability in Cisco Secure Email Gateway.Β
While the two zero-days disclosed this week have consecutive CVE identifiers, thereβs no indication they are connected or share any technical relationship, Rice said. βThese are different products and different vulnerability classes with no relation,β he added.
A Cisco spokesperson concurred with that assessment. βCVEs are assigned on a first-come, first-served basis, so consecutive numbering reflects assignment order rather than any relationship between the issues. CVE-2026-76460 and CVE-2026-76461 affect different codebases,β the spokesperson added.
Cisco published indicators of compromise to help customers hunt for attempted exploitation in their environments, and said there are no workarounds for the vulnerability.
Attackers of unknown origins and motivations are exploiting a critical zero-day vulnerability in Cisco Secure Email Gateway, authorities and researchers said Monday.
The vulnerability β CVE-2026-76461 βΒ was exploited before Cisco disclosed and patched the defect Monday and allows unauthenticated, remote attackers to execute commands with root privileges on vulnerable systems. βIn practical terms, that gives the attacker control of the gateway itself,β Douglas McKee, director of vulnerability intelligence at Rapid7, told CyberScoop.
Cisco said its product security incident response team became aware of active exploitation of the defect affecting Cisco AsyncOS Software for Cisco Secure Email Gateway in September. When asked for further details, a company spokesperson pointed to the advisory and reiterated that the company is aware of active exploitation of the vulnerability.
The company did not say how many organizations are impacted by active exploitation thus far, but it indicated multiple customers were likely compromised prior to disclosure.Β
βCisco has conducted a thorough threat intelligence investigation on devices that belong to Cisco Secure Email Cloud. Cisco has directly contacted customers who own Cisco Secure Email Cloud devices where indicators of possible compromise were identified,β the company wrote in its security advisory. βCisco is engaged in remediation and recovery operations. Cisco has already deployed mitigations that are within Ciscoβs management.β
The Cybersecurity and Infrastructure Security Agency added the zero-day, which affects cloud-based and on-premises instances of Cisco Secure Email Gateway, to its known exploited vulnerabilities catalog shortly after Ciscoβs disclosure.Β
The tight timeline between Ciscoβs public advisory and patch guidance, and CISAβs quick addition to the KEV catalog indicates the vulnerability deserves immediate attention, McKee said.Β
βThe combination here is pretty ugly. No authentication is required, an attacker can reach the vulnerable code by sending an email through the appliance, successful exploitation can result in root-level command execution, and Cisco has observed exploitation in the wild,β he added.
Researchers at Rapid7 and VulnCheck said they donβt yet know how many organizations are impacted by active exploits, but they encouraged Cisco customers to patch and hunt for potential signs of compromise as soon as possible.Β
Spencer McIntyre, director of exploit development at VulnCheck, told CyberScoop the exploit could allow an attacker to maintain access to the email gateway and monitor communications. βStealing or silently snooping on email comms is a common tactic for state-sponsored and other threat actors conducting espionage operations,β he said.Β
βItβs going to be worse for organizations that have the appliance deployed on-premises. In this case, the attacker could pivot internally,β McIntyre added. βIf, however, organizations use a cloud instance, the compromised gateway is less likely to have significant access to internal organizational resources.β
Cisco released indicators of compromise to help customers hunt for attempted exploitation in their environments, but the company added that attackers could remove or hide those traces with the level of access granted via exploitation.
Microsoft addressed 974 defects across its product suite, including two actively exploited zero-day vulnerabilities, in its monthly Patch Tuesday security program.Β
The massive batch of patches, Microsoftβs largest ever, reflects a continuing trend for the vendor as it leans on artificial intelligence to discover more vulnerabilities at a faster rate. Yet, the recent period of record breaking vulnerability disclosures hasnβt resulted in a flood of actively exploited zero-days.
βAI-assisted vulnerability discovery shows no signs of slowing down,β Dustin Childs, head of threat awareness at Trend Microβs Zero Day Initiative, wrote in a blog post Tuesday. βHowever, we have not seen a correlating spike in active exploits β yet.β
The vulnerabilities actively exploited prior to disclosure β CVE-2026-81963 affecting the Windows Update Stack and CVE-2026-85880 affecting Windows Advanced Local Procedure Call β both have CVSS ratings of 7.8 and allow attackers to escalate privileges.Β
More than 1 in 10 defects Microsoft disclosed in this monthβs security update are rated critical. The update included 723 vulnerabilities in Windows, 111 in Office, 111 in Office 2016, 62 in SQL and 22 spanning various developer tools.
Researchers encouraged security teams and customers to not get overwhelmed by the total number of defects, but instead focus on their specific areas of risk and exposure.Β
βWhile the number of vulnerabilities being patched is rising, the number of vulnerabilities that can and will affect most organizations remains quite low. AI-assisted vulnerability discovery in 2026 is creating larger haystacks, but it isnβt finding more needles,β Satnam Narang, senior staff research engineer at Tenable, said in an email.Β
βItβs critical that organizations understand which vulnerabilities actually apply to them, whether they pose a threat by being reachable and exploitable, and prioritize remediation based on this risk context,β he added.Β
Jack Bicer, director of vulnerability research at Action1, drew a similar conclusion from the record-breaking Patch Tuesday.Β
βAt this scale, the challenge is not simply getting through the patch list but knowing what needs attention first,β he said. βWith hundreds of updates landing at once, IT and security teams need to quickly separate the vulnerabilities that demand immediate action from those that can follow the normal deployment cycle.β
On August 27, 2026, PaperCut Software published an urgent security advisory stating that it is investigating active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF. PaperCut has confirmed customer incidents and is treating the issue as a security emergency. At the initial time of disclosure, the vulnerability had not been assigned a CVE identifier, and PaperCut had not publicly disclosed a CVSS score, vulnerability class, authentication requirements, or the technical details of the exploit path. However on August 28, the vendor assigned CVE-2026-81578 and CVE-2026-82078 for the two vulnerabilities that make up the exploit chain.
CVE ID
Description
CWE
CVSSv4
CVE-2026-81578
Authentication Bypass
CWE-306 Missing authentication for critical function.
PaperCut NG and PaperCut MF are print management platforms commonly deployed within enterprise, education, and other organizational environments. Because the PaperCut Application Server provides web-accessible administrative and application functionality, organizations with servers exposed to the public internet should prioritize remediation and access restriction.
PaperCut stated in its advisory that information supplied by a university customerβs security team and digital forensics and incident response team enabled its security response team to reproduce the vulnerability in PaperCut NG and PaperCut MF. On August 28, 2026 at 02:10 AEST, PaperCut released emergency patches for PaperCut NG and PaperCut MF versions 25 and 26, followed later the same day with patches for version 24.
PaperCut has been targeted in the past; in 2023, CVE-2023-27350 was broadly exploited in the wild by multiple threat-actor groups, including ransomware operators. This prior history increases the urgency organizations should address this new zero-day with.
PaperCut currently considers all versions of PaperCut NG and PaperCut MF potentially impacted. Customers operating internet-accessible PaperCut Application Servers should take immediate action even if no suspicious activity has been observed.
On August 31, 2026, both CVE-2026-81578 and CVE-2026-82078 were added to the U.S. Cybersecurity and Infrastructure Security Agencyβs (CISA) list of known exploited vulnerabilities (KEV), based on evidence of active exploitation. A Metasploit module is now available to validate exposure to the exploit chain.
Technical overview
The vulnerability is an authentication bypass that lets attackers invoke privileged PaperCut components. This can be leveraged to reconfigure an external database lookup. When this lookup is triggered, malicious SQL can be executed, resulting in remote code execution.
PaperCut uses the Apache Tapestry framework, whose "complex direct" request format can identify one page to display and a different page containing the component to execute. PaperCut validates access only to the displayed page. By selecting either the public Error page or Exception page for display, an attacker can bypass authentication while invoking administrative components belonging to ConfigEditor or UserList. Additionally, the first emergency patch could be bypassed by using the Home page for display, however the newest version of the vendor patch correctly remediates this bypass.
The attack uses HTTP POST requests to the following URIs (Note that the path segment with the value 1 shown below can be any value for this path segment, and the Error path segment may also be the Exception or Home path segment):
The first two URIs provide unauthenticated access to PaperCut's configuration editor. The third can invoke a user or card search that triggers the configured external database lookup.
An attacker first uses the ConfigEditor requests to modify four external user-lookup settings:
These settings normally allow administrators to connect PaperCut to an external card database. After bypassing authentication, however, the attacker can configure them with a malicious JDBC connection and a malicious SQL statement.
By leveraging PaperCut's bundled Apache Derby database driver and supplying a Derby CALL statement that activates its foreignViews feature, Derby opens an attacker-controlled H2 JDBC URL. H2 processes an inline INIT statement that creates a JavaScript-backed database trigger. PaperCut includes the Nashorn JavaScript engine, allowing that trigger to start an operating-system process. However it is expected that other mechanisms to execute an arbitrary command can also be used instead of Nashorn. Finally, the attacker submits a search through the forged UserList request. This activates the external lookup and executes the malicious SQL.
Mitigation guidance
Organizations running PaperCut NG or PaperCut MF should prioritize patching on an emergency basis, particularly where the PaperCut Application Server is accessible from the public internet.
PaperCut has released emergency patches for PaperCut NG and PaperCut MF versions 24, 25 and 26.Β
Updated on September 1, 2026: Note that the vendor has released a third version of the emergency patch. Any organization that has applied either the original first version or the second version of the emergency patch is not fully protected, and must apply the third emergency patch immediately.
The vendor notes that these builds have not undergone their normal release process and are intended as emergency fixes for customers with public-facing servers that cannot otherwise sufficiently mitigate exposure.
PaperCut recommends that administrators immediately restrict web access to trusted IP addresses only, such as internal corporate network ranges. Firewall rules, network access controls, reverse-proxy restrictions, or equivalent measures should be used to prevent untrusted internet hosts from reaching PaperCut web interfaces.
Please read the PaperCut security advisory for the latest remediation guidance, updated indicators of compromise, and additional release information.
Artifacts/Evidence Sources and IOCs
For detection and forensic analysis, PaperCut has identified several preliminary artifacts and evidence sources that may indicate compromise.
Application activity: Alerts from intrusion-detection, endpoint-security, or network-monitoring products involving the PaperCut Application Server, particularly suspicious post-exploitation activity associated with pc-app.exe.
Log integrity: Missing, unexpectedly truncated, or deleted PaperCut server.log files.
PaperCut server.log entries:
ERROR No suitable driver found for jdbc:no:x
ERROR DatabaseUtils - Database error looking up cardID: VALUES CAST
PaperCut has not yet published validated network-based indicators such as malicious IP addresses, domains, or URLs.
The vendor specifically warns that the absence of these indicators should not be interpreted as evidence that a system has not been affected.
Rapid7 customers
Exposure Command, InsightVM, and Nexpose
Exposure Command, InsightVM, and Nexpose customers can assess exposure to this new PaperCut zero-day, with an authenticated vulnerability check expected to be available in the August 28 (todayβs) content release.
Updates
August 28, 2026: Initial publication.
August 28, 2026: Updated to reflect new emergency patches and CVE ID assignment. Updated remediation to include the new v24 patches. Updated Technical Overview to indicate first patch bypass.
August 31, 2026: Updated the Overview to note that both CVEs were added to the CISA KEV list, and the availability of a Metasploit module.
September 1, 2026: Updated the Remediation section to reflect the vendor's new emergency patch (release 3).
A notorious cybercrime group has once again exploited a critical zero-day vulnerability on a large scale, claiming it stole data from dozens of organizations, including some of the worldβs largest publicly traded companies.
Clop, a prolific but calculated data theft extortion group thatβs been active since 2020, began sending threatening emails to its alleged victims in mid-July, according to researchers.Β
The fallout from the attack spree, which followed a familiar pattern for Clop and its targeted pool of victims, is still evolving as companies hunt for potential signs of compromise.
The vulnerability at the center of Clopβs latest campaign affects a pair of software products from PTC β Windchill and FlexPLM β which manufacturers and retailers, particularly in the manufacturing, aerospace, and automotive industries, use to automate supply chain systems and manage product lifecycles.
βThis continues Clopβs trend of targeting SaaS logistics companiesβ platforms with zero-days and carrying out mass-exploitation campaigns,β Allan Liska, field chief information security officer at Recorded Future, told CyberScoop.
Yet, that was too late for some of Clopβs known victims who were likely compromised by exploitation of the zero-day in early June, according to Ransom-ISAC.
The Cybersecurity and Infrastructure Security Agency added the defect, which allows unauthenticated attackers to execute code remotely, to its known exploited vulnerabilities catalog June 25.
PTC consistently added new indicators of compromise as they were discovered by researchers. But the company hasnβt said how it first became aware of the vulnerability and ensuing attacks, when the earliest known instance of exploitation occurred or how many customers are known to be compromised.Β
PTC did not respond to a request for comment.Β
Clopβs claimed victim set is diverse. The point-of-sale restaurant management platform Toast and software vendor Zebra both told CyberScoop they detected and contained system intrusions, but claimed limited impacts. Other alleged victims, including GE, Philips and Shell, did not respond to requests for comment.Β
Researchers continue to uncover new details about the tools Clop used once it exploited and gained access to PTC customer systems. ReliaQuest said the group used a custom web shell that gave attackers a direct path to credential theft and large-scale data theft.
The fully equipped extortion platform, which was purpose-built for Windchill, decrypts credentials, delivers malware, and includes tools for sustained access, network traversal and data encryption, ReliaQuest researchers wrote in a report Tuesday.
The toolkit allows attackers to move quickly from initial access to data theft and additional post-exploitation activity without executing manual commands β a framework that mimics Windchillβs standard functions and limits defendersβ ability to detect any malicious activity.
βThis campaign is another reminder that Clop remains a sleeping dragon, always looking and preparing to mass exploit vulnerabilities in software that holds sensitive data,β ReliaQuest researchers wrote in the report. βThe group commonly goes inactive between campaigns but springs to life with custom-built web shells whenever there is another opportunity for mass extortion.βΒ
The drawn-out impact of Clopβs latest attack spree also mirrors some of its previous campaigns. The threat group has successfully exploited zero-days across multiple technology vendorsβ systems, allowing it to steal sensitive data for weeks β sometimes months β from many downstream customers.
Clop targeted dozens of Oracle E-Business Suite customers for more than three months, beginning in the summer of 2025, before it started bombarding victims with extortion emails. The group also achieved mass exploitation as it infiltrated MOVEit environments in 2023, ultimately exposing data from more than 2,300 organizations, making it the largest and most significant cyberattack that year.