Compiled from 52 monitored sources · 120 articles reviewed
Today’s Briefing
Attackers are exploiting CVE-2026-81578 and CVE-2026-82078 in PaperCut to steal credentials and gain privileged access in education-sector attacks across the United States and Europe, according to Arctic Wolf researchers. A separate unpatched vulnerability in Magento Open Source and Adobe Commerce, named StyleSmuggler by Sansec, is being exploited in the wild to execute malicious code on online store servers without authentication, with attacks beginning on 4 September. JetBrains disclosed that threat actors exploited a critical TeamCity vulnerability to breach its Cadence environment and extract AWS credentials, prompting the company to urge all Cadence users to revoke and rotate credentials immediately.
Top Stories
- PaperCut Flaws Exploited in Attacks on U.S. and European Schools
- Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
- Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials
Full brief available to subscribers
The complete operator brief — action items with patch deadlines, the vulnerability appendix and named actor activity — goes out by email each morning. Subscribe free to receive it.