Saturday, August 29, 2026
Daily digest
Heavy vulnerability day: ServiceNow, PaperCut, ownCloud, and router firmware all saw critical flaws with active exploitation or KEV additions — prioritize patching triage today.
Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL
ServiceNow patched four vulnerabilities in its AI Platform, three rated a perfect 10.0 CVSS score and exploitable by unauthenticated attackers in certain configurations. The company pushed the fix to hosted instances automatically but self-hosted and partner-managed instances must apply the update manually.
Why it matters: If ServiceNow is used for ITSM/ticketing in your environment, confirm whether your instance is self-hosted or partner-managed — those don't get the automatic fix and need immediate manual patching to avoid unauthenticated RCE/SQLi.
PaperCut Releases Second Emergency Patch as Attackers Chain Flaws for Unauthenticated Code Execution
PaperCut issued a second emergency patch for PaperCut NG and MF after researchers found bypasses for its initial fix; attackers are actively chaining two flaws to gain unauthenticated remote code execution by hijacking the application's trusted configuration. The first patch proved insufficient, prompting the additional hardening release.
Why it matters: PaperCut is common in government/education print environments; apply the second patch immediately rather than relying on the first — the initial fix was already bypassed in the wild.
ownCloud Flaw Added to CISA KEV After Use Against Philippine Nuclear Research Body
CISA added CVE-2023-49105 (CVSS 9.8), an ownCloud vulnerability, to its Known Exploited Vulnerabilities catalog after a Chinese-speaking threat actor used it to steal nuclear records from a Philippine research institution. The flaw allows attackers to bypass authentication controls in ownCloud deployments.
Why it matters: KEV additions carry federal remediation deadlines under BOD 22-01; if ownCloud is anywhere in your environment or a subcontractor's, confirm patch status now for CMMC/800-171 due-diligence purposes.
China-Made ZBT Routers Ship With Two Factory Implants Giving Root Access
VulnCheck disclosed two previously undocumented firmware implants — SPEAKINGSTONE and DARKLANTERN (CVE-2026-74232, CVE-2026-74233) — baked into routers made by Shenzhen Zhibotong Electronics (ZBT). Both give unauthenticated remote attackers root-level command execution on affected devices.
Why it matters: This is a supply-chain hardware risk relevant to CMMC's prohibition on covered defense telecom/networking equipment from certain foreign manufacturers — audit any OEM/white-label ZBT-based gear in your network inventory.
McKesson Discloses Breach After ShinyHunters Claims 284 Million Patient Records Stolen
Healthcare distribution giant McKesson disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft. The ShinyHunters extortion group claims to have stolen 284 million patient data records in the attack.
TerminalFix Campaign Uses Fake CAPTCHAs and DLL Sideloading to Deploy Reverse Tunnels
Microsoft Threat Intelligence documented a multistage ClickFix-style campaign dubbed TerminalFix that lures victims with fake CAPTCHA prompts, then uses DLL sideloading to establish a reverse tunnel for persistent remote access. Microsoft published detection rules and hunting guidance for defenders.
Why it matters: ClickFix-style social engineering continues to bypass EDR via fake CAPTCHAs; push the Microsoft hunting queries into Defender/Sentinel and reinforce user awareness training for this specific lure pattern.
Over 8,300 Gitea Servers Still Vulnerable to Remote Code Execution
Shadowserver reports more than 8,300 internet-exposed Gitea instances remain unpatched against a critical RCE flaw currently under active exploitation. Gitea is a self-hosted Git service used widely as a lightweight GitHub alternative.
Why it matters: If Gitea backs any internal automation or Ansible playbook repositories, verify patch status and internet exposure immediately — self-hosted git servers are a high-value target for supply-chain compromise.
Judge Rules Pentagon's Anthropic Ban Was 'Illegal and Baseless'
A federal district judge ruled that the Trump administration's actions against Anthropic, including the Pentagon's designation of the company as a supply chain risk, were unlawful retaliation and not supported by evidence of a genuine national security threat. The ruling invalidates the government's attempt to punish and ban the AI company.
Why it matters: For agencies or contractors that paused Anthropic/Claude usage due to the supply-chain-risk designation, this ruling reopens the question of whether self-hosted or API-based Claude use can resume in your AI stack pending appeal.
Quantum Security 'Drumbeat' Set to Grow Louder in Federal Procurement
CISA's top quantum security expert said federal agencies will need to work closely with industry as post-quantum cryptography requirements increasingly show up in procurement and contracting language. The comments came alongside separate reporting that DOD is probing industry on software-defined encryption approaches to accelerate its quantum-safe migration.
Why it matters: Start tracking NIST PQC algorithm migration timelines now — future CMMC/800-171 revisions and DoD contract clauses are likely to mandate quantum-resistant crypto for CUI-handling systems.
Trump Administration Moves to Block Risky Foreign Technology From US Power Grid
A new executive order targets hardware, software, and remote-access services from designated foreign adversaries in the US power grid, potentially requiring operators to isolate or replace equipment already in use. The order expands supply-chain restrictions previously focused on telecom into the energy sector.
Why it matters: This signals the direction of broader federal supply-chain restrictions likely to extend to defense contractors — review vendor/BOM lists for foreign-origin networking and industrial control components now, ahead of similar rules touching CMMC scope.
AWS Adds Private Access to Extend Data Perimeter to Management Console
AWS announced Private Access, a new capability letting organizations restrict access to the AWS Management Console itself to authorized accounts and private network paths, removing the previous requirement for public internet connectivity to reach the console. It's aimed at regulated industries including government and defense that isolate sensitive workloads.
Why it matters: This closes a longstanding data-perimeter gap for AWS GovCloud environments — evaluate enabling Private Access to eliminate console-level internet exposure and strengthen 800-171 boundary protection controls (SC-7).
Windows 11 KB5120998 Preview Update Released With 35 Changes
Microsoft released the KB5120998 preview cumulative update for Windows 11 versions 25H2 and 24H2, delivering 35 changes and fixes including improvements to the Start menu, taskbar, and Windows search.
Why it matters: This is a preview/optional update — test via your Intune ring before broad deployment given the Register's note this week on 24H2/25H2's recent history of buggy servicing-branch updates.