TL;DR
TerminalFix (new ClickFix variant) targets Windows Terminal users with fake Cloudflare CAPTCHAs to install backdoors. Five critical WordPress plugins patched for account takeover and RCE. PaperCut NG/MF actively exploited via chained vulnerabilities; emergency patch released. Microsoft patched 398 flaws including one zero-day already under attack.
Executive Summary
- TerminalFix, a new ClickFix social-engineering variant, targets Windows Terminal and PowerShell users with fake Cloudflare CAPTCHA pages to trick them into executing malicious commands that deploy reverse-tunnel backdoors.
- Five critical vulnerabilities in WordPress plugins—WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP—enable authentication bypass, account takeover, and arbitrary code execution; patches are available.
- PaperCut NG and MF are under active exploitation via a newly patched chain of two vulnerabilities that allow unauthenticated remote code execution; the vendor released an emergency fix with additional hardening.
- Microsoft released 398 security updates covering Windows and supported software, including one vulnerability already being actively exploited and two others publicly disclosed before the patch.
- Berlin's state government confirmed it is the target of an extortion attempt following August compromise of its administrative network and refused ransom demands; forensic investigation found additional data outflows.
Top Threats Today
1. TerminalFix ClickFix Variant Deploys Reverse-Tunnel Backdoor via Fake CAPTCHAs
Severity: High Affected: Technology
Microsoft has disclosed a new ClickFix variant dubbed TerminalFix that applies the traditional ClickFix social-engineering technique to Windows Terminal and PowerShell users [1]. Rather than directing victims to the Windows Run dialog, TerminalFix campaigns use fake Cloudflare CAPTCHA pages to deceive users into running malicious commands [1]. The goal is to deploy a reverse-tunnel backdoor, granting attackers remote control over compromised systems [1].
Sources:[1] The Hacker News
Recommended Action
- Advise users that legitimate CAPTCHAs will not request command execution in Terminal or PowerShell
- Monitor endpoint logs for suspicious PowerShell or Terminal activity triggered by user interactions
- Consider restricting direct user access to PowerShell execution on sensitive workstations
2. Five Critical WordPress Plugins Patched for Account Takeover and RCE
Severity: High Affected: Technology
Multiple critical security flaws have been disclosed in five widely-used WordPress plugins: WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP [1]. These vulnerabilities enable authentication bypass, account takeover, and arbitrary code execution, posing a significant risk to WordPress site administrators and users [1]. Patches are available from vendors Wordfence and Patchstack ⚠[1].
Sources:[1] The Hacker News
Recommended Action
- Audit current versions of WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP across all WordPress installations
- Apply vendor patches immediately to affected plugins
- Consider temporarily disabling plugins until patches are verified and tested in a staging environment
- Monitor WordPress user accounts and authentication logs for unauthorized activity
3. PaperCut NG and MF Actively Exploited via Chained Vulnerabilities; Emergency Patch Released
Severity: High Affected: Technology
Malicious actors are actively exploiting a newly patched security flaw in PaperCut NG and MF that chains two vulnerabilities together [1]. This vulnerability allows an unauthenticated attacker to gain remote code execution and control over susceptible PaperCut instances [1]. PaperCut released an emergency patch with additional hardening to address the flaw [1].
Sources:[1] The Hacker News[2] The Record
Recommended Action
- Immediately apply PaperCut's emergency patch to all NG and MF installations
- Segment print management infrastructure from general enterprise networks if not already done
- Review print server access logs for unauthorized command execution or administrative activity
- Monitor for lateral movement from compromised print servers to network shares or domain controllers
4. Microsoft Patch Tuesday: 398 Vulnerabilities Including Active Zero-Day Exploitation
Severity: High Affected: Technology
Microsoft released updates to remedy at least 398 security vulnerabilities in Windows operating systems and supported software ⚠[1]. The patch set includes one vulnerability that is already being actively exploited in the wild, as well as two others that were publicly disclosed prior to today's ⚠ release [1].
Sources:[1] The Hacker News
Recommended Action
- Prioritize deployment of Microsoft updates addressing the actively exploited zero-day and two publicly disclosed vulnerabilities
- Test patches in a non-production environment before broad rollout to critical systems
- Monitor enterprise systems for signs of exploitation during and after patching
- Review vendor advisory to identify CVEs affecting your deployed Microsoft product versions
5. Berlin State Government Breached; Refuses Ransom After Secondary Data Exfiltration Confirmed
Severity: High Affected: Government
Berlin's state government has confirmed it is the target of an extortion attempt following an August compromise of the city's state administrative network [1]. The government stated it will not meet the extortionists' demands [1]. Forensic work conducted after the breach has found further data outflows beyond the initial compromise, indicating more extensive unauthorized access than initially disclosed [1].
Sources:[1] The Hacker News
Recommended Action
- If operating critical infrastructure or government-aligned networks, review logs for indicators of compromise matching the Berlin incident timeline (August 2026)
- Increase monitoring for ransom communications or data staging on publicly accessible breach notification sites
- Coordinate with law enforcement and maintain transparency with stakeholders regarding breach scope and remediation
Today’s Action Checklist
- ☐ URGENT: Patch PaperCut NG and MF instances against actively exploited chained vulnerabilities
- ☐ URGENT: Apply Microsoft patches for the actively exploited zero-day and prioritize the two publicly disclosed CVEs
- ☐ URGENT: Audit and patch WordPress installations running WPMU DEV Dashboard, Avada, TranslatePress, Pods, or GiveWP
- ☐ HIGH: Brief users and helpdesk staff on TerminalFix fake-CAPTCHA lures; remind them that legitimate CAPTCHAs do not request Terminal/PowerShell commands
- ☐ MEDIUM: Review third-party incident response contacts and ensure ransomware response playbook is current