Security.io Intelligence DeskWednesday, 2 September 2026
Independent analysis
for security executives
The Security.io DailyThe Weekday Intelligence Edition
Free to readers
Supported by underwriters
Today’s lead:PaperCut Release 3 supersedes earlier fixes as exploitation continuesJack Henry confirms vishing-led extortion incidentBoston Scientific recovery remains incomplete after global disruptionAWS and Azure introduce a jointly managed private interconnect
Front page · Daily intelligence

PaperCut Release 3 supersedes earlier fixes as exploitation continues

CISA’s KEV action and a third emergency patch turn PaperCut remediation into a patch-plus-compromise-assessment decision.

Active exploitation is confirmed for a pre-authentication PaperCut NG/MF code-execution chain. Emergency Patch Release 3, published shortly before this edition, supersedes the two previous emergency releases and requires organisations to revalidate both patch state and compromise state.

Why today: The underlying issue was disclosed on 27 August, but the decision changed twice inside this edition’s window: CISA placed both flaws in KEV on 31 August, and Release 3 superseded both earlier emergency patches at 4:22 a.m. ET…
“Inventory every PaperCut NG/MF Application Server, version, owner and internet exposure.”

Decision owner: CISO with infrastructure, print services and incident response

Decision horizon: Immediate: isolate now; patch and assess compromise before normal business operations.

Continue the lead analysis →

Full source ledger, evidence of closure and escalation triggers appear in the article.

1Dominant story selected for executive consequence
4Supporting developments, tightly edited
7 minTarget time to understand today’s priorities
0Programmatic banners, pop-ups or paywalls

Today’s ledger

Selected for consequence, not headline volume
Lead decision

PaperCut Release 3 supersedes earlier fixes as exploitation continues

Active exploitation is confirmed for a pre-authentication PaperCut NG/MF code-execution chain. Emergency Patch Release 3, published shortly before this edition, supersedes the two previous emergency releases…

Today’s action: Inventory every PaperCut NG/MF Application Server, version, owner and internet exposure.

Identity

Jack Henry confirms vishing-led extortion incident

Jack Henry confirmed that ShinyHunters used vishing to reach a limited internal, non-production environment. The company reported no client-facing or core-service disruption, but said PII associated…

Today’s action: Request written confirmation of whether your institution’s data was affected.

Resilience

Boston Scientific recovery remains incomplete after global disruption

Boston Scientific’s latest update narrows the observed technical activity to certain on-premises systems and reports no additional malicious activity since detection.

Today’s action: Map clinical, manufacturing and logistics dependencies on affected Boston Scientific services.

Incident Response

ATF says CALEA data-publication claims remain unverified

ATF’s new update acknowledges claims that material concerning investigative matters was published from its standalone CALEA system. The agency cannot yet confirm authenticity, nature or scope…

Today’s action: Validate sensitive-data inventories for standalone investigative platforms.

Signal desk

Interactive editorial evidence
Lead-story decision pressure

PaperCut response priority

Hover or tap a bar for its exact value and the editorial meaning behind it. Keyboard: focus the chart and use ↑ or ↓.

Security.io editorial 0–100 scores. Exposure reflects potential internet reach and installed-base relevance; Urgency reflects active exploitation and superseded emergency patches; Business Consequence reflects privileged server placement and compromise uncertainty. These are not vendor CVSS metrics.

Higher scores indicate greater executive consequence, urgency and decision value. Security.io editorial scoring is a prioritisation aid, not a prediction of incident probability.Source: Security.io editorial score derived from the cited PaperCut, CISA, Huntress and Rapid7 evidence
Evidence accumulated across the edition

Verified references behind today’s five decisions

Hover or tap a point to see the story title, new references, cumulative evidence, source mix and why the story entered today’s edition. Keyboard: use ← or →.

This line shows cumulative cited references across the lead and four supporting briefs.

primary: 7 · research: 2 · reporting: 4 · context: 2

Appointments, dinners & sponsored intelligence

Paid placements · clearly separated
Open calendar
Sponsor's Notice · Security.io

Private CISO Roundtable: The 2027 Security Agenda

A closed-door, vendor-neutral discussion for senior security leaders hosted by Security.io.

Request details →
Invitation only
Sponsor's Notice · Security.io

Security.io CISO Dinner: Decisions That Cannot Wait

An invitation-only dinner for CISOs and deputies focused on consequential security decisions.

Request an invitation →
Black Hat week
Paid Placement · Security.io

Security.io at Black Hat: Executive Intelligence Dinner

A private dinner and briefing for security leaders during Black Hat week.

Join the interest list →