02 SEP 2026 · 15:01 MDT · AFTERNOON DELTA: Guildma/Astaroth localized delivery analysis and September Windows Server baseline-reboot planning added. Read authoritative brief →
02 SEP 2026 · 15:01 MDT · SEV 1: Active Proxmox VE 7 exploitation and the Virtualizor update-channel incident elevate virtualization/HPC control-plane response. Read authoritative brief →

ZIAWOLF // SEC INTEL

Current threat signal

A decision-ready view of the latest authoritative ZiaWolf Threat Intelligence Brief. Full provenance, archive and source register are maintained at GavinLujan.com.

PAPERCUT ACTIVE EXPLOITATION

A patch is not an all-clear.

SEV 1 CRITICAL · REDCONFIDENCE · HIGHSTATUS · NEW CISA KEV LISTING / ACTIVE EXPLOITATIONNEXT UPDATE · 03 SEPTEMBER 2026 · 06:00 MDT

PaperCut Release 3 remains the priority. CISA refreshed catalog metadata without adding entries. Microsoft’s TerminalFix analysis documents fake CAPTCHA instructions leading to user execution, persistence and a reverse tunnel; the full brief contains safe detection and containment guidance.

ATT&CK: T1190 Exploit Public-Facing Application; T1059 Command and Scripting Interpreter; T1505 Server Software Component.

PROPOSED MITIGATION — REQUIRES ENVIRONMENT-SPECIFIC VALIDATION: Restrict PaperCut management access and install Release 3; hunt before closure. Isolate HPC control planes, harden identities and scheduler APIs, sign software artifacts, monitor storage/fabric egress, and validate power, cooling, provider and model continuity.

READ FULL LATEST BRIEF →VIEW ARCHIVEAI + HPC DASHBOARD