View all sources for this day →

The Signal

The day’s most consequential material spans reported intrusion activity, software-delivery infrastructure, a cloud-platform data-access incident, regulatory reporting, and criminal accountability. Across these distinct stories, the editorial priority is to keep confirmed events separate from the wider systems, dependencies, and obligations that each event places under scrutiny in operational practice. [1][2][3][4][5]

Must Know

AI & Agents · Helpnetsecurity

AI & Agents · Exploitation

What happened

According to GreyNoise, a threat actor built an exploit for PaperCut print-management software and used AI agents to conduct most of the intrusion work against organizations. [1]

The reported campaign compromised at least 440 PaperCut instances across 395 identified organizations in 48 countries. [1]

Why it matters

The reported scale and use of an attacker-prepared test environment suggest that organizations running PaperCut NG/MF should reassess exposure and intrusion-detection coverage; the evidence does not establish that AI agents can independently compromise all such environments. [1]

Exploitation · The Hacker News

Supply Chain · Exploitation

What happened

Wiz reported that attackers chained two flaws in JFrog Artifactory to gain administrator control of self-hosted servers and plant backdoors. [2]

Wiz observed the attacks between August 15 and September 8. [2]

Why it matters

Artifactory is used as a repository that software build pipelines pull from, linking exploitation of affected self-hosted servers to build-pipeline infrastructure. [2]

Cloud · Helpnetsecurity

Cloud · Incident

What happened

IDScan confirmed that hackers accessed customer data stored on its cloud platform after reports linked the company to a dark-web database containing more than 153 million driver’s-license scans. [3]

IDScan processes identity checks for car-rental companies, retailers, and cannabis dispensaries. [3]

Why it matters

Because the service supports identity checks across several customer-facing sectors, confirmed access should be assessed as a dependency exposure, not as evidence that any particular customer was compromised. [3]

Exploitation · Theregister Security

Policy · Security

What happened

The Cyber Resilience Act’s Article 14 reporting duties are now applicable to manufacturers of products with digital elements made available in the EU, subject to exemptions, regardless of where manufacturers are based. [4]

Manufacturers must submit an early warning within 24 hours of becoming aware of an actively exploited vulnerability, followed by a detailed notification within 72 hours. [4]

Why it matters

Failures to comply with these reporting duties, classified as core responsibilities under the Act, could lead to the maximum CRA fines: up to €15 million or 2.5% of annual turnover, whichever is higher. [4]

Incident · Theregister Security

Incident · Security

What happened

Oleksii Oleksiyovych Lytvynenko, a Ukrainian-trained lawyer who later lived in Cork, Ireland, was sentenced to four years in a U.S. prison after pleading guilty to conspiracy to commit wire fraud for his role in the Conti ransomware operation. [5]

Using the handle “henry,” Lytvynenko joined a Conti team as an intruder and developer and was directed to code a malware loader designed to run additional malicious code on a victim’s machine. [5]

Why it matters

Evidence showed he possessed data stolen from eight U.S. victims and four overseas victims; the U.S. victims reported more than $1.5 million in losses. [5]

Also Worth Knowing

Security · Helpnetsecurity

Security · Platform

What happened

Ubuntu 24.04.5 LTS installation media bundles security updates and fixes for high-severity bugs for the Noble Numbat release. [6]

Sources (6)
  1. [1] AI agents exploited PaperCut flaws to breach 395 organizations

    helpnetsecurity · September 11, 2026

  2. [2] Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors

    the hacker news · September 11, 2026

  3. [3] IDScan confirms breach after 153 million driver’s licenses leak on dark web

    helpnetsecurity · September 11, 2026

  4. [4] EU's Cyber Resilience Act starts the 24-hour vulnerability clock

    theregister security · September 11, 2026

  5. [5] Ukrainian lawyer's second career as a Conti coder earns him 4 years behind bars

    theregister security · September 11, 2026

  6. [6] Ubuntu 24.04.5 LTS release patches security bugs across ten flavors

    helpnetsecurity · September 11, 2026

Security Daily · September 11, 2026 · Baitaphish