📋 Top Headlines at a Glance
- PaperCut Flaws Exploited in AI-Powered Attacks
- Kiteworks expands runtime data governance with Bonfy.AI acquisition
- Trezor: 347,000 users targeted in phishing attacks after Brevo breach
- Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors
- UK Council Attack Linked to Mass Exploitation of SonicWall Flaw
Executive Summary: Today’s intelligence highlights a critical surge in the exploitation of known vulnerabilities across diverse platforms, from print management systems like
PaperCutto software repositories likeJFrog Artifactoryand network security appliances fromSonicWall. A concerning development is the observed use of AI by a Russian threat actor to accelerate exploit development and deployment. Concurrently, large-scale phishing campaigns, exemplified by theBrevobreach impacting Trezor users, underscore persistent supply chain risks. In the vendor space, strategic acquisitions like Kiteworks’ purchase of Bonfy.AI signal a market shift towards real-time, runtime data governance to address evolving data protection challenges.
🌍 Technical Intelligence Breakdown
🤖 PaperCut Flaws Exploited in AI-Powered Attacks
A Russian threat actor has been observed leveraging artificial intelligence (AI) to enhance their offensive capabilities. This actor utilized AI to develop, test, and deploy exploits targeting PaperCut flaws against hundreds of organizations globally.
Key points:
- Threat Actor: A Russian-aligned group.
- Methodology: AI was employed in the exploit lifecycle, from creation to deployment.
- Target:
PaperCutvulnerabilities. - Impact: Hundreds of organizations worldwide have been affected.
Critical Callout: The use of AI by threat actors represents an escalation in sophistication, potentially enabling faster weaponization of vulnerabilities and broader attack campaigns.
Defensive Actions:
- Immediately patch all
PaperCutinstances to the latest secure versions. - Implement robust intrusion detection and prevention systems to monitor for exploitation attempts.
- Conduct regular security audits and penetration testing to identify and remediate potential weaknesses.
🤝 Kiteworks expands runtime data governance with Bonfy.AI acquisition
Kiteworks has acquired Bonfy.AI, a strategic move aimed at expanding its runtime data governance capabilities. This acquisition is designed to enable organizations to govern data exchanges in real-time, regardless of whether the exchange is initiated by a person, machine, or autonomous agent. The move addresses a perceived structural gap in how enterprises protect sensitive data, complementing existing data discovery and posture management efforts.
Strategic Positioning:
| Aspect | Before Acquisition | After Acquisition |
|---|---|---|
| Data Governance Scope | Data at Rest (Discovery/Posture) | Data in Motion (Runtime Exchanges) |
| Data Exchange Control | Limited real-time oversight | Real-time, person/machine/agent-driven |
| Problem Addressed | Data inventory & static posture | Dynamic data exchange protection |
This acquisition highlights an industry trend towards more dynamic and real-time data protection solutions, moving beyond static data inventories to govern data as it flows through an enterprise.
🎣 Trezor: 347,000 users targeted in phishing attacks after Brevo breach
Following a breach at an entity identified as Brevo, approximately 347,000 users of Trezor were targeted in a widespread phishing campaign. Of those targeted, 2,500 users clicked on malicious links embedded in the phishing emails.
Key points:
- Root Cause: A breach affecting
Brevo. - Attack Vector: Phishing emails.
- Target Audience: 347,000 Trezor users.
- Affected Users: 2,500 users clicked malicious links.
Defensive Actions:
- Educate users on identifying and reporting phishing attempts, emphasizing vigilance against unsolicited communications.
- Implement advanced email security solutions, including DMARC, DKIM, and SPF, to prevent spoofing and detect malicious content.
- Encourage the use of hardware security keys and multi-factor authentication (MFA) for critical accounts.
- Regularly review and secure third-party vendor access to sensitive data, as supply chain breaches can lead to significant downstream impact.
⛓️ Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors
Attackers successfully chained two distinct flaws within JFrog Artifactory to achieve administrator control over self-hosted servers and subsequently plant backdoors. These attacks were observed between August 15 and September 8. It is important to note that JFrog had already released fixes for both vulnerabilities prior to these observed attacks, meaning only unpatched servers were susceptible.
Attack Path:
JFrog Artifactory Flaw 1 ➡️ JFrog Artifactory Flaw 2 ➡️ Administrator Control ➡️ Backdoor Deployment
Key points:
- Target: Self-hosted
JFrog Artifactoryservers. - Method: Chaining of two known vulnerabilities.
- Impact: Full administrator control and backdoor installation.
- Vulnerability Status: Patches were available before the attacks were observed.
Defensive Actions:
- Immediately apply all available patches and updates for
JFrog Artifactoryinstances. - Implement continuous vulnerability scanning and patch management processes for all critical software, especially those in the software supply chain.
- Monitor
JFrog Artifactoryserver logs for unusual activity, unauthorized access, or the creation of new user accounts. - Segment build environments and apply least privilege principles to limit potential lateral movement if a compromise occurs.
🇬🇧 UK Council Attack Linked to Mass Exploitation of SonicWall Flaw
A critical SonicWall flaw was rapidly weaponized and exploited in a campaign that included an attack on a UK Council. This exploitation led to the exposure of credentials and enabled Active Directory theft. The Borough Council of King’s Lynn and West Norfolk publicly announced detecting a cyberattack affecting its services on July 17, 2026, with subsequent analysis linking it to the mass exploitation of the SonicWall vulnerability.
Key points:
- Target: UK Council (Borough Council of King’s Lynn and West Norfolk).
- Vulnerability: Critical
SonicWallflaw. - Impact: Exposed credentials, Active Directory theft.
- Weaponization: Rapidly weaponized and exploited in a mass campaign.
Defensive Actions:
- Apply all security patches and updates for
SonicWalldevices without delay. - Implement strong password policies and multi-factor authentication (MFA) for all user accounts, especially those with administrative privileges.
- Monitor Active Directory for suspicious activity, including unauthorized access attempts, privilege escalation, or unusual account modifications.
- Regularly back up critical data and systems, and test recovery plans.
- Conduct incident response drills to ensure preparedness for similar attacks.
📉 Threat Landscape & Trends
- Persistent Vulnerability Exploitation: Known vulnerabilities in widely used enterprise software (
PaperCut,JFrog Artifactory,SonicWall) continue to be primary targets, underscoring the critical importance of timely patching. - AI as an Offensive Enabler: The observed use of AI by a Russian threat actor to build, test, and deploy exploits marks a significant evolution in attack capabilities, potentially leading to faster and more sophisticated campaigns.
- Supply Chain Risk Amplification: Breaches affecting third-party service providers, as seen with
Brevoimpacting Trezor users, demonstrate the cascading effect of supply chain vulnerabilities and the need for robust vendor risk management. - Phishing Remains Effective: Despite advancements in security, large-scale phishing campaigns continue to successfully compromise users, highlighting the enduring human element in cybersecurity.
- Evolving Data Governance: The market is responding to dynamic data protection needs with strategic acquisitions focused on runtime data governance, moving beyond static data discovery to real-time control over data exchanges.
📌 Strategic Takeaway
Organizations must prioritize proactive vulnerability management and rapid patching across their entire digital estate, including critical infrastructure and supply chain components, while simultaneously investing in advanced threat detection and robust user education to counter increasingly sophisticated and AI-augmented attacks.
🔗 References
- PaperCut Flaws Exploited in AI-Powered Attacks
- Kiteworks expands runtime data governance with Bonfy.AI acquisition
- Trezor: 347,000 users targeted in phishing attacks after Brevo breach
- Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors
- UK Council Attack Linked to Mass Exploitation of SonicWall Flaw