PaperCut’s Sunday indicators make compromise review mandatoryMcKesson confirms third-party data theft but leaves customers…Factory firmware implants make ZBT-derived routers an asset-trust…ATF incident shows why standalone does not mean low consequence
Monday flagship · Weekend decision brief
PaperCut’s Sunday indicators make compromise review mandatory
Sunday’s indicators transformed the PaperCut emergency from a patching task into a forensic one. Internet-facing NG and MF servers require isolation, Emergency Patch Release 2 verification and evidence-led compromise review before closure.
Security.io Intelligence Desk · Monday, 31 August 2026
Executive consequence
PaperCut confirmed active exploitation of an unauthenticated PaperCut NG/MF chain and issued two emergency patch iterations before the weekend.
Decision today
Remove public access to every PaperCut Application Server pending verified Release 2 deployment.
McKesson discovered the incident on 25 August and filed an SEC Form 8-K on Friday. Its Saturday customer update confirmed unauthorised access to certain third-party applications and data exfiltration associated with a subset of customers in Oncology & Multispecialty and Medical-Surgical.
Do today
Request customer-specific impact confirmation from McKesson through contractual and support channels.
VulnCheck identified SPEAKINGSTONE and DARKLANTERN in firmware shipped with ZBT and white-labelled routers. The components provide unauthenticated root command execution: one through cleartext outbound command-and-control traffic and the other through an inbound UDP service.
Do today
Inventory cellular, branch and edge routers by OEM, model, firmware and MAC prefix.
ServiceNow disclosed CVE-2026-18885, CVE-2026-18886 and CVE-2026-74820, each scored CVSS 4.0 10.0 and affecting the ServiceNow AI Platform. The flaws permit unauthenticated code injection, privilege escalation or SQL injection.
Do today
Classify every ServiceNow instance as vendor-hosted, partner-hosted or self-hosted.
ATF disclosed a designated major incident affecting a standalone system and said its enterprise network, eForms and mission remained unaffected. On Friday, its public affairs chief told CyberScoop that the system contained information about targets of ATF investigations.
Do today
Inventory isolated and legacy systems holding investigative, regulatory or highly sensitive data.