Security.io Intelligence DeskThursday, 3 September 2026
Independent analysis
for security executives
The Security.io DailyThe Weekday Intelligence Edition
Free to readers
Supported by underwriters
PaperCut’s Sunday indicators make compromise review mandatoryMcKesson confirms third-party data theft but leaves customers…Factory firmware implants make ZBT-derived routers an asset-trust…ATF incident shows why standalone does not mean low consequence
Monday flagship · Weekend decision brief

PaperCut’s Sunday indicators make compromise review mandatory

Sunday’s indicators transformed the PaperCut emergency from a patching task into a forensic one. Internet-facing NG and MF servers require isolation, Emergency Patch Release 2 verification and evidence-led compromise review before closure.

Executive consequence

PaperCut confirmed active exploitation of an unauthenticated PaperCut NG/MF chain and issued two emergency patch iterations before the weekend.

Decision today

Remove public access to every PaperCut Application Server pending verified Release 2 deployment.

Decision intelligence, not a headline feed.Every edition ranks what security leaders should read first, assign today and monitor next.
Six-minute executive briefing

Security.io Daily Headlines

Five equally weighted stories: what happened and the leadership decision each creates.

Read today’s headlines

The weekend decision ledger

What changed · Why it matters · What to do
02
Third-Party Risk

McKesson confirms third-party data theft but leaves customers without application scope

Why it matters

McKesson discovered the incident on 25 August and filed an SEC Form 8-K on Friday. Its Saturday customer update confirmed unauthorised access to certain third-party applications and data exfiltration associated with a subset of customers in Oncology & Multispecialty and Medical-Surgical.

Do today

Request customer-specific impact confirmation from McKesson through contractual and support channels.

Read the briefing →
03
Supply Chain

Factory firmware implants make ZBT-derived routers an asset-trust problem

Why it matters

VulnCheck identified SPEAKINGSTONE and DARKLANTERN in firmware shipped with ZBT and white-labelled routers. The components provide unauthenticated root command execution: one through cleartext outbound command-and-control traffic and the other through an inbound UDP service.

Do today

Inventory cellular, branch and edge routers by OEM, model, firmware and MAC prefix.

Read the briefing →
05
Incident Response

ATF incident shows why standalone does not mean low consequence

Why it matters

ATF disclosed a designated major incident affecting a standalone system and said its enterprise network, eForms and mission remained unaffected. On Friday, its public affairs chief told CyberScoop that the system contained information about targets of ATF investigations.

Do today

Inventory isolated and legacy systems holding investigative, regulatory or highly sensitive data.

Read the briefing →

Signal desk

Evidence that changes prioritisation
Monday decision pressure

PaperCut lead-story decision profile

Security.io scores each dimension from 0–100. Exposure reflects reachable affected estates, urgency reflects exploitation and remediation time, and business consequence reflects privileged placement and credible post-compromise impact. Source: Security.io editorial scoring based on the selected PaperCut primary and research sources.

Back page

Daily comic · Circuit Chuckles
A brief pause after the intelligence

Clean Desk Policy

Rusty interprets the clean desk policy as literally cleaning the desk while exposing confidential documents.

Monday, 31 August 2026Open comic page →
In a four-panel black-and-white newspaper comic, Glitch audits a clean desk policy while Rusty washes the desk and leaves confidential papers hanging on a clothesline to dry.