logo

TerminalFix backdoor, WordPress plugin RCEs, PaperCut chain exploit; Microsoft patches 398 vulns

ID: d4847baf-00ef-50e5-b062-db44b020acbb

STIX ID: report--d4847baf-00ef-50e5-b062-db44b020acbb

Feed Name: defend.network

Threat Score
80/100

Date Published: 2026-08-31

Date Updated: 2026-08-31

Author: defend.network

...
...

**TL;DR:** Multiple high‑risk incidents: TerminalFix (a ClickFix variant) uses fake Cloudflare CAPTCHAs to trick Windows Terminal/PowerShell users into installing reverse‑tunnel backdoors; five widely used WordPress plugins were patched for authentication bypass, account takeover and RCE; PaperCut NG/MF is being actively exploited via a chained unauthenticated RCE and an emergency patch was released; Microsoft released fixes for 398 vulnerabilities including one zero‑day already exploited; and Berlin's state government confirmed data exfiltration and extortion. Immediate actions recommended include patching PaperCut and Microsoft critical updates, updating or disabling affected WordPress plugins, briefing users on social‑engineering lures, and reviewing logs and incident response readiness.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.