Daily Cyber Threat Intel Brief — 2026-08-29
Generated: 2026-08-29 08:02:41 UTC
Executive summary
Priority technology watch items
- Overview On August 27, 2026, PaperCut Software published an urgent security advisory stating that it is investigating active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF. PaperCut has confirmed customer incidents and is treating the…
- Concurrent execution using shared resource with improper synchronization ('race condition') in Copilot Chat (Microsoft Edge) allows an authorized attacker to disclose information over a network.
- Improper neutralization of parameter/argument delimiters in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
- Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
- Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.
- Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.
- Public RansomLook extortion-site listing claim. Group: lynx. Claimed victim/listing: cutlercapital. Description excerpt: Cutler Capital Management, LLC of Worcester, MA is an investment advisory firm r...
- PaperCut NG and PaperCut MF are under active exploitation. Huntress reproduced a pre-auth RCE chain and shares urgent patching and exposure guidance.
Newly exploited vulnerabilities / CVE watch
Ransomware and extortion trend notes
Malware / infrastructure / abuse feed highlights
IOC highlights
| Type | Value | Context | Source |
| cve | `CVE-2026-81578` | PaperCut NG/MF Critical Zero-Day Exploited in the Wild | Rapid7 Blog |
| cve | `CVE-2026-82078` | PaperCut NG/MF Critical Zero-Day Exploited in the Wild | Rapid7 Blog |
| cve | `CVE-2026-58616` | CVE-2026-58616 Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-66323` | CVE-2026-66323 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-66798` | CVE-2026-66798 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-70341` | CVE-2026-70341 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-72984` | CVE-2026-72984 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-70331` | CVE-2026-70331 Microsoft Edge for iOS Spoofing Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-62904` | CVE-2026-62904 Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-66324` | CVE-2026-66324 Microsoft Edge (Chromium-based) Spoofing Vulnerability | Microsoft Security Response Center RSS |
| cve | `CVE-2026-78891` | Chromium: CVE-2026-78891 Buffer overflow in WebRTC | Microsoft Security Response Center RSS |
| cve | `CVE-2026-78892` | Chromium: CVE-2026-78892 Incorrect authorization in Chromoting | Microsoft Security Response Center RSS |
| cve | `CVE-2026-78893` | Chromium: CVE-2026-78893 Information leak in QUIC | Microsoft Security Response Center RSS |
| cve | `CVE-2026-78894` | Chromium: CVE-2026-78894 Race condition in Payments | Microsoft Security Response Center RSS |
| cve | `CVE-2026-78895` | Chromium: CVE-2026-78895 Information leak in Paint | Microsoft Security Response Center RSS |
| cve | `CVE-2026-78896` | Chromium: CVE-2026-78896 Information leak in StorageAccessAPI | Microsoft Security Response Center RSS |
| cve | `CVE-2026-78897` | Chromium: CVE-2026-78897 Missing authorization in BrowserTag | Microsoft Security Response Center RSS |
| cve | `CVE-2026-78898` | Chromium: CVE-2026-78898 Incorrect authorization in Downloads | Microsoft Security Response Center RSS |
| cve | `CVE-2026-78899` | Chromium: CVE-2026-78899 Use after free in V8 | Microsoft Security Response Center RSS |
| cve | `CVE-2026-78900` | Chromium: CVE-2026-78900 Improper input validation in Media | Microsoft Security Response Center RSS |
| cve | `CVE-2026-78901` | Chromium: CVE-2026-78901 Race condition in V8 | Microsoft Security Response Center RSS |
| cve | `CVE-2026-78903` | Chromium: CVE-2026-78903 Incomplete cleanup in SiteIsolation | Microsoft Security Response Center RSS |
| cve | `CVE-2026-78904` | Chromium: CVE-2026-78904 Type confusion in ANGLE | Microsoft Security Response Center RSS |
| cve | `CVE-2026-78905` | Chromium: CVE-2026-78905 Type confusion in ANGLE | Microsoft Security Response Center RSS |
| cve | `CVE-2026-78906` | Chromium: CVE-2026-78906 Race condition in ANGLE | Microsoft Security Response Center RSS |
| cve | `CVE-2026-78907` | Chromium: CVE-2026-78907 Incorrect authorization in WebProtect | Microsoft Security Response Center RSS |
| cve | `CVE-2026-78908` | Chromium: CVE-2026-78908 Information leak in Canvas | Microsoft Security Response Center RSS |
| ipv4 | `185.100.157.222` | URLhaus: malware_download URL observed (offline) | URLhaus Recent URLs |
| ipv4 | `50.16.16.211` | Feodo Tracker: 1 recommended botnet C2 IPs listed | Feodo Tracker Recommended Blocklist |
| hash | `1f9182de04597cb54beb4537be5582aa` | RansomLook: apatpa.com claimed by lockbit5 | RansomLook Recent Listings |