AFTERNOON BRIEF // 01 SEPTEMBER 2026

Protect the boundary. Verify the evidence.

PaperCut Release 3 remains the top response priority. CISA refreshed its KEV catalog metadata today without adding entries. New in this edition: Microsoft’s TerminalFix campaign analysis, which connects fake CAPTCHA instructions to staged execution, persistence and a reverse tunnel—not a newly disclosed vulnerability.

OVERALL · SEV 2 HIGH · ORANGENEXT UPDATE · 02 SEPTEMBER 2026 · 06:00 MDT

EXECUTIVE ACTION MAP · GUIDANCE, NOT LIVE TELEMETRY

Exposure → evidence → recovery

  1. RED · CONTAIN
    Restrict PaperCut exposure
  2. ORANGE · VERIFY
    Close applicable KEV actions
  3. YELLOW · TEST
    Validate rules and agent authority
  4. GREEN · PROVE
    Demonstrate clean recovery

Colors here identify action stages, not measured control health.

01 // ACTIVE EXPLOITATION

PaperCut Release 3 supersedes earlier emergency patches.

SEV 1 CRITICAL · REDCONFIDENCE · HIGHSTATUS · ACTIVE EXPLOITATION / RELEASE 3 AVAILABLE

Confirmed: PaperCut published Emergency Patch Release 3 on September 1 at 18:22 AEST (02:22 MDT). It supersedes Release 2, adds hardening and corrects broken SAML login plus legacy Microsoft SQL Server driver support. CISA lists CVE-2026-81578 and CVE-2026-82078 as known exploited, due September 14; ransomware use is recorded as unknown. Assessment: patch completion alone cannot establish that an exposed server was never compromised.

ATT&CK: T1190 Exploit Public-Facing Application; T1059 Command and Scripting Interpreter.

PROPOSED MITIGATION — REQUIRES ENVIRONMENT-SPECIFIC VALIDATION: Restrict web access to trusted addresses; apply Release 3 per vendor instructions; preserve logs and examine unexpected Java classes, command/output files and missing logs. Investigate suspicious systems, rotate affected credentials and test SAML/Card-ID workflows after patching. Absence of artifacts is not clearance.

PaperCut · updated September 1 · Huntress · independent exploitation research

02 // EXPLOITED VULNERABILITIES

ownCloud and Linux: verify closure after August 30 deadlines.

SEV 2 HIGH · ORANGECONFIDENCE · HIGHSTATUS · EXISTING KEV ENTRIES / DEADLINES PASSED

Confirmed: The retrieved CISA-maintained snapshot is version 2026.09.01, released September 1 at 19:22:46 UTC, with 1,687 entries. It lists August 30 due dates for ownCloud CVE-2023-49105 and Linux CVE-2026-53362. Artifactory CVE-2026-66384 is due September 10. These three entries are carry-forward; the two new PaperCut entries are covered above. Ransomware use is recorded as unknown for these three.

ATT&CK: T1190 Exploit Public-Facing Application; T1068 Exploitation for Privilege Escalation (behavioral relevance; not attribution).

PROPOSED MITIGATION — REQUIRES ENVIRONMENT-SPECIFIC VALIDATION: Inventory affected ownCloud, distro kernels and Artifactory installations; verify vendor applicability, deploy supported fixes and verify running versions. Drain HPC jobs before kernel maintenance and reboot where required. Record exposure, evidence and owner sign-off; apply federal requirements only where applicable.

CISA official repository snapshot · ownCloud advisory · NVD cross-reference

03 // HPC CONTROL PLANE

Slurm REST belongs behind a trusted boundary.

SEV 2 HIGH · ORANGECONFIDENCE · HIGHSTATUS · DOCUMENTED ARCHITECTURE RISK / NO NEW INCIDENT CLAIM

Confirmed: SchedMD states that slurmrestd is not designed for direct internet exposure and requires external transport protection for access outside the cluster. It recommends short-lived JWTs and an authenticating proxy. Assessment: scheduler authority can convert stolen identities into compute misuse or access to valuable research; this is not evidence of a breach at any named cluster.

ATT&CK: T1078 Valid Accounts; T1552 Unsecured Credentials; T1496 Resource Hijacking.

PROPOSED MITIGATION — REQUIRES ENVIRONMENT-SPECIFIC VALIDATION: Remove direct public access; use a trusted network and an authenticated TLS proxy with SSO/MFA, short-lived tokens and connection limits. Run with appropriate unprivileged identities. Audit scheduler actions, unusual jobs and storage egress; rehearse partition isolation.

SchedMD REST security documentation · reviewed August 30 · MITRE T1496

04 // AI + HPC WORKLOAD ISOLATION

OpenShell: critical sandbox boundaries need patching.

SEV 1 CRITICAL · REDCONFIDENCE · HIGH ON ADVISORYSTATUS · VENDOR-CONFIRMED / EXPLOITATION NOT CONFIRMED

Confirmed: NVIDIA’s bulletin, initially released August 25 and updated August 28, lists OpenShell CVE-2026-65093 and CVE-2026-65083 at CVSS 9.9. Versions 0 through 0.0.33 are affected; v0.0.34 addresses these issues. The bulletin also lists separate NemoClaw fixes. Assessment: compromised workload isolation threatens adjacent research, model and service credentials; this is not a confirmed exploitation report.

ATT&CK: T1611 Escape to Host; T1068 Exploitation for Privilege Escalation (analyst risk mappings, not observed behavior).

PROPOSED MITIGATION — REQUIRES ENVIRONMENT-SPECIFIC VALIDATION: Upgrade affected OpenShell to v0.0.34 or a supported later fixed release. Inventory NemoClaw separately against its component-specific fixes; restrict API exposure, scope credentials, isolate untrusted workloads and hunt unexpected processes or egress.

NVIDIA security bulletin · August 25 / updated August 28

05 // NATION-STATE / CRITICAL INFRASTRUCTURE

QTFY disruption does not certify victim recovery.

SEV 2 HIGH · ORANGECONFIDENCE · HIGH ON DOJ RECORDSTATUS · CARRY-FORWARD / DOJ UPDATED AUGUST 28

Confirmed: DOJ describes QScan/QTRouter infrastructure disruption and alleged services to PRC state customers. Its press release was edited to align with the affidavit. Assessment: infrastructure seizure is not proof of eradication at affected organizations. Preserve distinctions between scanning, attempted compromise and documented successful intrusion; do not expand victim claims.

ATT&CK: T1595 Active Scanning; T1190 Exploit Public-Facing Application; T1090 Proxy (analyst mapping).

PROPOSED MITIGATION — REQUIRES ENVIRONMENT-SPECIFIC VALIDATION: Review vulnerable perimeter systems and IoT gateways, correlate historic telemetry with official guidance, investigate persistence and preserve evidence. Do not whitelist a source merely because its apparent address is domestic. Keep OT boundaries isolated.

DOJ/FBI · updated August 28, reviewed August 30

06 // AI-ENABLED RISK

AI malware: sample counts are not current prevalence.

SEV 3 ELEVATED · YELLOWCONFIDENCE · MEDIUMSTATUS · HISTORICAL VENDOR RESEARCH / PREVENTIVE ASSESSMENT

Confirmed: Unit 42 examined 405 AI-associated samples; 12 appeared on Cortex XDR-protected endpoints. Endpoint telemetry covers December 2024–June 2025, and network telemetry June 2024–June 2025. Samples span AI branding, generated code and functional AI use. Assessment: this vendor-specific, historical dataset is not a current global attack rate or proof of widespread autonomous malware. Keep behavior-based controls and agent permissions under test.

ATT&CK: T1195.002 Compromise Software Supply Chain; T1528 Steal Application Access Token (risk mappings, not observed events).

PROPOSED MITIGATION — REQUIRES ENVIRONMENT-SPECIFIC VALIDATION: Sandbox agent execution; allowlist packages and registries; scope credentials and egress; require approval for consequential writes; log tool calls and evaluate prompt-injection resistance. Re-test controls after model/provider changes.

Unit 42 · AI-enabled malware analysis, historical telemetry

07 // RANSOMWARE / PUBLIC SECTOR

Recovery evidence must include research and OT dependencies.

SEV 2 HIGH · ORANGECONFIDENCE · MEDIUMSTATUS · PREPAREDNESS ASSESSMENT / NO NEW VICTIM CLAIM

Established behavior: MITRE documents encryption for impact. Assessment: shared storage, identity services and backup administration can concentrate downtime across public services, HPC research and data-center operations. This edition does not confirm a new ransomware incident or actor claim.

ATT&CK: T1486 Data Encrypted for Impact; T1490 Inhibit System Recovery.

PROPOSED MITIGATION — REQUIRES ENVIRONMENT-SPECIFIC VALIDATION: Keep immutable/offline backups with separate administration, test restores and key recovery, record recovery objectives, and exercise identity loss plus parallel-storage failure. Validate OT-safe containment with process owners and confirm supplier recovery obligations.

MITRE T1486 · reviewed August 30

08 // AI + HPC CAPACITY RESILIENCE

Power forecasts are not commissioned capacity.

SEV 3 ELEVATED · YELLOWCONFIDENCE · HIGH ON SOURCE / MEDIUM ON ASSESSMENTSTATUS · PLANNING ASSESSMENT / NO NEW ATTACK

Source fact: IEA’s 2025 Energy and AI report distinguishes estimated historical demand from scenario-based forecasts and identifies longer energy-infrastructure lead times. Assessment: reserved power, leases and proposed campuses do not establish usable AI/HPC capacity. Confirm commissioning, redundancy and actual service availability separately.

ATT&CK: No direct mapping for energy forecasting. Cyber disruption of supporting systems is a separate scenario requiring its own evidence.

PROPOSED MITIGATION — REQUIRES ENVIRONMENT-SPECIFIC VALIDATION: Require evidence of grid energization, cooling acceptance, network readiness and workload tests before treating capacity as available. Validate UPS/generator and provider failover plans; identify BMS/OT owners and rehearse safe loss-of-capacity responses.

IEA · 2025 report, reviewed August 30 · Dated energy infographic

09 // COLLABORATION / IDENTITY

Spring Ring: verify the help desk before granting control.

SEV 2 HIGH · ORANGECONFIDENCE · HIGH ON VENDOR OBSERVATIONSSTATUS · NEW REPORT / JANUARY–APRIL ACTIVITY

Confirmed: Unit 42’s August 31 report describes external Teams accounts impersonating IT support, targeting over 150 employees at at least 10 companies during January–April 2026. Calls led to remote-management tools or malware; one analyzed path attempted lateral movement. The researchers report no evidence of a Microsoft product compromise or vulnerability in this campaign. Assessment: trusted collaboration channels need independent identity verification, including for research and HPC operators.

ATT&CK: T1566.004 Spearphishing Voice; T1219 Remote Access Tools (analyst mappings).

PROPOSED MITIGATION — REQUIRES ENVIRONMENT-SPECIFIC VALIDATION: Require callback through a known internal directory; restrict external Teams access as business needs allow; approve remote-support tools centrally. Correlate external chats/calls with unexpected remote-control activity and privileged access. Isolate suspicious endpoints and revoke affected sessions.

Unit 42 · published August 31; observed January–April 2026

10 // AI MODEL SUPPLY CHAIN

A model endpoint can impersonate capability—and authority.

SEV 2 HIGH · ORANGECONFIDENCE · MEDIUM-HIGHSTATUS · HONEYPOT OBSERVATION / ARCHITECTURE RISK

Confirmed: SANS ISC describes a honeypot resembling an Ollama endpoint that was discovered and subsequently used by third parties expecting models the endpoint did not offer. SANS warns an untrusted model endpoint could return content that influences a coding agent to execute commands. Assessment: this demonstrates model-endpoint provenance risk; it does not prove compromise of Ollama, Anthropic or any named model vendor.

ATT&CK: T1195.002 Compromise Software Supply Chain; T1557 Adversary-in-the-Middle (risk mappings, not confirmed activity).

PROPOSED MITIGATION — REQUIRES ENVIRONMENT-SPECIFIC VALIDATION: Allowlist model endpoints and pin certificates/providers; authenticate both client and service; block discovery ports from the internet. Sandbox coding agents, scope secrets and egress, require approval for command execution, and log endpoint identity, model identifier and tool calls.

SANS ISC diary · September 1 · SANS Stormcast · September 1

11 // TERMINALFIX / USER EXECUTION

A fake CAPTCHA can become a network foothold.

SEV 2 HIGH · ORANGECONFIDENCE · HIGH ON MICROSOFT OBSERVATIONSSTATUS · OBSERVED CAMPAIGN / REPORT PUBLISHED AUGUST 28

Confirmed: Microsoft describes compromised websites presenting fake CAPTCHA instructions that persuade users to paste commands into Windows Terminal. The documented chain uses staged execution, DLL sideloading, persistence, discovery and an outbound reverse tunnel. Microsoft’s ATT&CK mapping includes T1189, T1059.001, T1204.002, T1547.001 and T1053.005. Assessment: user-executed “verification” commands can turn browser trust into durable network access; this edition does not attribute ransomware deployment or a new victim.

ATT&CK: T1189 Drive-by Compromise; T1059.001 PowerShell; T1204.002 Malicious File; T1547.001 Registry Run Keys; T1053.005 Scheduled Task.

PROPOSED MITIGATION — REQUIRES ENVIRONMENT-SPECIFIC VALIDATION: Train users never to paste verification commands from websites; enable PowerShell script-block logging and constrained language where supportable. Restrict unapproved tunneling and remote-access tools, alert on suspicious scheduled tasks/DLL loads, isolate affected endpoints and rotate exposed credentials.

Microsoft Security · August 28, reviewed September 1 · SANS ISC · September 1 coverage

PROVENANCE + COLLECTION LIMITS

Evidence first; no artificial freshness.

Edition: September 1 PM. Last updated 01 SEPTEMBER 2026 · 15:02 MDT. This afternoon, PaperCut, CISA’s official repository mirror, Microsoft’s TerminalFix report and SANS ISC were retrieved. CISA’s catalog metadata advanced to version 2026.09.01 at 19:22:46 UTC while the count remained 1,687; no new KEV entry is inferred. PaperCut still lists Release 3 as the current emergency patch. Other cards retain their original event/source dates as carry-forward assessments. NVD and FIRST EPSS did not provide usable new enrichment; no score is fabricated.

Vendor and public-source discovery was incomplete: CrowdStrike, Talos, Google Threat Intelligence/Mandiant, Microsoft, FortiGuard, SentinelOne, Sophos, Rapid7, Shadowserver, FBI and MS-ISAC were not all substantively reverified this afternoon. No new ransomware or nation-state incident is confirmed by this edition. This is a coverage gap, not evidence of no activity. “Group 42” is not used as an alias for Google/Mandiant; Palo Alto’s Unit 42 is a distinct research team.

STIX 2.1 is a representation standard; TAXII 2.1 is transport. MISP and OpenCTI are aggregation, enrichment and correlation platforms, not original evidence. No live feed ingestion or STIX/TAXII service is claimed. Deduplicate by CVE, campaign and source event; retain original references and corrections. EPSS estimates exploitation probability, not observed exploitation; KEV inclusion records known exploitation. Severity here is editorial response priority, not CVSS or a finding about Gavin’s networks.

Confidence describes the cited fact or clearly labeled assessment. ATT&CK mappings are analyst interpretations unless explicitly attributed. No malware, exploit payloads, secrets, personal data or harmful live indicators are included.

Previous AM edition · AI + HPC dashboard