THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
AI agents turn PaperCut exploitation into a large-scale, semi-automated breach pipeline

Security researchers say an attacker used AI agents to build and deploy PaperCut NG/MF exploits across hundreds of organizations. GreyNoise-linked findings indicate at least 440 PaperCut instances were compromised across 395 organizations in 48 countries. The key takeaway for defenders: patching is only part of the story—organizations need fast detection and containment for “time-to-compromise” when automation accelerates exploitation.

Source: Help Net Security


IDScan.net confirms breach after 153 million driver’s license scans leak

IDScan.net has confirmed unauthorized access to customer data following reporting that a dark web database contained more than 153 million driver’s license scans. The company attributes the incident to information it received indicating certain data “may have been” compromised on or around September 1. This highlights how identity verification vendors become high-value targets—and how breaches can create long-lived fraud and account-takeover risk for downstream customers.

Source: Help Net Security


Critical GitLab path traversal (CVE-2026-85706) probed and exploited within hours

A critical GitLab path traversal flaw (CVSS 10.0) can allow unauthenticated attackers to read arbitrary files via the commits API. Multiple reports note in-the-wild probing very shortly after disclosure, emphasizing how quickly attackers move once a high-severity bug becomes public. Organizations running self-managed GitLab should prioritize patching, and then validate that web-exposed management endpoints are segmented and monitored for abnormal access patterns.

Source: SecurityWeek


Check Point patches two critical VPN gateway bugs (remote code execution risk)

Check Point addressed two critical vulnerabilities affecting VPN gateways, tracked as CVE-2026-85102 and CVE-2026-85103. The flaws could enable remote code execution, meaning exposed gateways can become direct footholds if exploited. The “watch item” for CISOs: ensure accelerated patch SLAs for edge appliances and confirm that VPN exposure is minimized and protected by strong authentication, logging, and incident-ready monitoring.

Source: SecurityWeek


Brevo email marketing breach triggers phishing campaigns targeting crypto users

Reports indicate a Brevo marketing platform breach exposed customer accounts and enabled threat actors to send convincing phishing emails to affected crypto communities. Trezor, CoinTracking, and BitBox users were specifically cited, with Trezor saying more than 347,000 users received phishing messages. This is a reminder that supply-chain-like weaknesses in third-party messaging infrastructure can rapidly translate into credential theft at scale—even when primary systems remain uncompromised.

Source: SecurityWeek


Conti ransomware: a developer sentenced in the U.S., continuing pressure on the core ecosystem

A Ukrainian national connected to the Conti ransomware operation was sentenced to four years in U.S. prison for his role in the group’s activity. Conti reportedly targeted more than 1,000 victims globally before shutting down in 2022. While takedowns and sentences disrupt capacity, defenders should treat “post-shutdown” as an evolution point—other ransomware affiliates and code-sharing ecosystems often reuse tactics, tooling, and affiliates.

Source: The Record (RecordedFuture)


You May Also Be Interested In...

PaperCut flaws exploited in AI-powered attacks
Attackers exploit critical Cisco FMC flaw to deploy Qilin ransomware
EU Cyber Resilience Act starts the 24-hour vulnerability clock

Cybersecurity — September 12, 2026 | Briefing24