Exchange Auth Bypass, PaperCut Data Theft, and Softaculous Supply Chain Attack

Exchange Auth Bypass, PaperCut Data Theft, and Softaculous Supply Chain Attack

•

Episode description

Exchange Auth Bypass, PaperCut Data Theft, and Softaculous Supply Chain Attack

Nearly 22,000 Microsoft Exchange servers remain unpatched for a critical authentication bypass vulnerability allowing complete mailbox takeover. PaperCut print management software, deployed across thousands of UK offices, is actively exploited for data theft days after a patch was released. A 33-hour BGP hijack of Softaculous infrastructure may have poisoned the hosting supply chain for small business websites. This briefing provides specific verification steps for IT providers, explains why the window between patch release and exploitation continues to shrink, and connects these incidents to wider supply chain and social engineering threats including Teams vishing campaigns and fake CAPTCHA attacks. For UK small businesses running on-premises Exchange, PaperCut installations, or shared hosting websites, today’s combination represents direct and immediate exposure requiring same-day action.

Chapters

  • Introduction Three active threats with direct paths into UK small business environments: 22,000 unpatched Exchange servers, active PaperCut exploitation for data theft, and a 33-hour BGP hijack of Softaculous infrastructure.
  • CVE-2026-62911: Exchange Authentication Bypass High-severity vulnerability allowing unauthenticated attackers to hijack all user mailboxes on 22,000 internet-exposed Exchange servers. Verification steps for IT providers and the organisational failure behind persistent Exchange patching delays.
  • Listener Call to Action Encouragement to follow the show and share with those running on-premises Exchange or shared hosting sites.
  • PaperCut Zero-Day Exploitation and Active Data Theft Two PaperCut vulnerabilities patched last week now actively exploited for data theft campaigns. The shrinking window between patch release and exploitation, and why data theft differs from ransomware in detection and response.
  • Softaculous BGP Hijack and Supply Chain Exposure Explanation of BGP hijacking mechanism and the 33-hour interception of Softaculous traffic affecting shared hosting infrastructure. Supply chain attack implications for small business websites and required audit steps.
  • Wider Threat Context Connections between today’s threats and broader patterns including Teams vishing campaigns, ClickFix fake CAPTCHA attacks, and the shift from perimeter to user-focused initial access vectors.
  • Closing Actions and Summary Three immediate actions: verify Exchange patch status, confirm PaperCut updates and check for prior compromise, audit shared hosting credentials and installations. Service level agreement implications if IT providers cannot respond within one working day.

Links

No transcript available for this episode.