Security news.
Today's cybersecurity news is dominated by widespread outages affecting Microsoft Exchange Online and ChatGPT, alongside critical vulnerability disclosures and active exploitation. CISA has added two PaperCut NG/MF vulnerabilities to its KEV catalog, emphasizing the urgency of patching known exploited flaws.
CISA Adds Two PaperCut NG/MF Vulnerabilities to KEV Catalog
CISA has added CVE-2026-81578 (Missing Authentication) and CVE-2026-82078 (Unsafe Reflection) affecting PaperCut NG/MF to its Known Exploited Vulnerabilities Catalog, urging immediate remediation.
Microsoft Warns of TerminalFix Attacks Deploying Reverse Tunnels
A new ClickFix variant, "TerminalFix," uses fake Cloudflare CAPTCHA prompts to trick users into running malicious PowerShell commands in Windows Terminal, leading to reverse tunnel deployment.
ServiceNow Patches 3 Critical Code Injection Vulnerabilities
ServiceNow has released patches for three critical code injection flaws that could allow attackers to execute arbitrary code, or access and tamper with data on affected systems.
Nightmare Eclipse Drops 'HardBreacher' Kaspersky Product Exploit
An exploit named 'HardBreacher' targeting a vulnerability in Kaspersky Endpoint Security has been released by the Nightmare Eclipse group, though Kaspersky confirms the flaw has been patched.
Microsoft Exchange Online Outage Causes Email Failures, Auth Issues
Microsoft is investigating a widespread service issue affecting Exchange Online customers, leading to authentication problems, email delays, and delivery failures.
OpenAI Confirms ChatGPT Outage as Users Report Errors
ChatGPT Work is experiencing a partial outage, with users reporting difficulties starting or continuing tasks across various subscription plans.
Berlin Confirms Data Theft After Rhysida Ransomware Attack Claims
Berlin's city administration has confirmed data theft and an extortion attempt by the Rhysida ransomware gang, who listed the city on their data leak site.
North Korean Job Fraud Expands Beyond IT Into Healthcare and Sales
North Korean threat actors are broadening their job fraud schemes beyond the IT sector, with investigations revealing suspected workers in sales, marketing, and medical professions.