Today’s lead:PaperCut Release 3 supersedes earlier fixes as exploitation continuesJack Henry confirms vishing-led extortion incidentBoston Scientific recovery remains incomplete after global disruptionAWS and Azure introduce a jointly managed private interconnect
Front page · Daily intelligence
PaperCut Release 3 supersedes earlier fixes as exploitation continues
CISA’s KEV action and a third emergency patch turn PaperCut remediation into a patch-plus-compromise-assessment decision.
By Security.io Intelligence Desk · Executive analysis
Active exploitation is confirmed for a pre-authentication PaperCut NG/MF code-execution chain. Emergency Patch Release 3, published shortly before this edition, supersedes the two previous emergency releases and requires organisations to revalidate both patch state and compromise state.
Why today: The underlying issue was disclosed on 27 August, but the decision changed twice inside this edition’s window: CISA placed both flaws in KEV on 31 August, and Release 3 superseded both earlier emergency patches at 4:22 a.m. ET…
“Inventory every PaperCut NG/MF Application Server, version, owner and internet exposure.”
Decision owner: CISO with infrastructure, print services and incident response
Decision horizon: Immediate: isolate now; patch and assess compromise before normal business operations.
Active exploitation is confirmed for a pre-authentication PaperCut NG/MF code-execution chain. Emergency Patch Release 3, published shortly before this edition, supersedes the two previous emergency releases…
Today’s action: Inventory every PaperCut NG/MF Application Server, version, owner and internet exposure.
Jack Henry confirmed that ShinyHunters used vishing to reach a limited internal, non-production environment. The company reported no client-facing or core-service disruption, but said PII associated…
Today’s action: Request written confirmation of whether your institution’s data was affected.
Boston Scientific’s latest update narrows the observed technical activity to certain on-premises systems and reports no additional malicious activity since detection.
Today’s action: Map clinical, manufacturing and logistics dependencies on affected Boston Scientific services.
ATF’s new update acknowledges claims that material concerning investigative matters was published from its standalone CALEA system. The agency cannot yet confirm authenticity, nature or scope…
Today’s action: Validate sensitive-data inventories for standalone investigative platforms.
AWS and Microsoft have opened public preview access to provider-managed private connectivity between their clouds.
Today’s action: Require security architecture approval before joining the preview.
Signal desk
Interactive editorial evidence
Lead-story decision pressure
PaperCut response priority
Hover or tap a bar for its exact value and the editorial meaning behind it. Keyboard: focus the chart and use ↑ or ↓.
Security.io editorial 0–100 scores. Exposure reflects potential internet reach and installed-base relevance; Urgency reflects active exploitation and superseded emergency patches; Business Consequence reflects privileged server placement and compromise uncertainty. These are not vendor CVSS metrics.
Hover or tap a point to see the story title, new references, cumulative evidence, source mix and why the story entered today’s edition. Keyboard: use ← or →.
This line shows cumulative cited references across the lead and four supporting briefs.