PaperCut Release 3 supersedes earlier fixes as exploitation continuesJack Henry confirms vishing-led extortion incidentBoston Scientific recovery remains incomplete after global disruptionAWS and Azure introduce a jointly managed private interconnect
Tuesday • 1 September 2026 • 06:00 ET · Executive decision brief
PaperCut Release 3 supersedes earlier fixes as exploitation continues
CISA’s KEV action and a third emergency patch turn PaperCut remediation into a patch-plus-compromise-assessment decision.
Security.io Intelligence Desk · Tuesday, 1 September 2026
Executive consequence
Active exploitation is confirmed for a pre-authentication PaperCut NG/MF code-execution chain. Emergency Patch Release 3, published shortly before this edition, supersedes the two previous emergency releases and requires organisations to revalidate both patch state and compromise state.
Decision today
Inventory every PaperCut NG/MF Application Server, version, owner and internet exposure.
Jack Henry confirmed that ShinyHunters used vishing to reach a limited internal, non-production environment. The company reported no client-facing or core-service disruption, but said PII associated with fewer than 10 clients was impacted and that an extortion attempt followed.
Do today
Request written confirmation of whether your institution’s data was affected.
Boston Scientific’s latest update narrows the observed technical activity to certain on-premises systems and reports no additional malicious activity since detection.
Do today
Map clinical, manufacturing and logistics dependencies on affected Boston Scientific services.
ATF’s new update acknowledges claims that material concerning investigative matters was published from its standalone CALEA system. The agency cannot yet confirm authenticity, nature or scope and continues to say other operational systems and mission delivery were unaffected.
Do today
Validate sensitive-data inventories for standalone investigative platforms.
Security.io editorial 0–100 scores. Exposure reflects potential internet reach and installed-base relevance; Urgency reflects active exploitation and superseded emergency patches; Business Consequence reflects privileged server placement and compromise uncertainty. These are not vendor CVSS metrics. Source: Security.io editorial score derived from the cited PaperCut, CISA, Huntress and Rapid7 evidence.
Back page
Daily comic · Circuit Chuckles
A brief pause after the intelligence
Air Gap
Rusty mistakes network isolation for creating literal airflow between two connected systems.