Compiled from 52 monitored sources · 470 articles reviewed
Today’s Briefing
CISA added CVE-2026-81578 and CVE-2026-82078 to the Known Exploited Vulnerabilities catalogue today, both affecting PaperCut NG/MF. The first is a missing authentication flaw allowing unauthenticated remote modification of system configuration; the second is an unsafe reflection vulnerability permitting arbitrary Java bytecode execution under the PaperCut server process context. CISA notes the two can be chained. Separately, Unit 42 published research on Spring Ring, a voice phishing campaign abusing Microsoft Teams to deploy malware targeting enterprise domain controllers.
Top Stories
- CISA Adds Two Known Exploited Vulnerabilities to Catalog
- Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams
- Financially Motivated Threat Actor BREEZE COMET Targets Brazil
Full brief available to subscribers
The complete operator brief — action items with patch deadlines, the vulnerability appendix and named actor activity — goes out by email each morning. Subscribe free to receive it.