Threat Analysis : Cyber News for Small Business
Threat Analysis : Cyber News for Small Business 0 followers
Follow
Zero-Day Print Server Exploits, Teams Vishing, and Firmware Implants

Zero-Day Print Server Exploits, Teams Vishing, and Firmware Implants

Aug 28, 2026 • 17min 36s

Episode description

Zero-Day Print Server Exploits, Teams Vishing, and Firmware Implants

This episode examines three active threats targeting UK small businesses through infrastructure that is often managed inattentively. PaperCut print management servers face active zero-day exploitation with no official vendor patch available, forcing organisations to choose between unvalidated emergency fixes or taking systems offline. A Microsoft Teams vishing campaign, running since January 2026, uses social engineering and the legitimate Windows Quick Assist tool to deploy the GoGRPC backdoor for ransomware operators. Research into ZBT router firmware reveals three pre-installed implants, including DARKLANTERN, an unauthenticated backdoor offering root shell access. The episode also covers critical ServiceNow vulnerabilities, over 8,300 unpatched Gitea instances facing active exploitation, and CISA’s observation that most exploited vulnerabilities in 2026 should have been eradicated decades ago. The common thread is infrastructure that organisations do not actively monitor: print servers, router firmware, and remote access tools that staff use without scrutiny. Mauven provides specific, actionable guidance for each threat, emphasising that the surfaces receiving least attention from defenders are those being studied most carefully by attackers.

Chapters

  • Introduction Overview of three active threats targeting infrastructure that UK small businesses manage inattentively: a print server zero-day, an eight-month Teams vishing campaign, and firmware implants in routers.
  • PaperCut Zero-Day: Active Exploitation, No Official Patch PaperCut print management servers face active zero-day exploitation with no validated vendor patch. The software, widely deployed in UK SMBs, has administrative access to networked devices and was previously exploited by ransomware groups in 2023. Organisations must choose between applying an unvalidated emergency patch or taking servers offline.
  • Call to Action Brief listener engagement request.
  • Microsoft Teams Vishing: GoGRPC Backdoor and the Ransomware Pipeline Zscaler research details an eight-month campaign using Microsoft Teams vishing and the legitimate Windows Quick Assist tool to deploy the GoGRPC backdoor. Attackers impersonate IT support, gain remote access, and sell network access to ransomware operators. The attack exploits normalised IT support behaviours.
  • Firmware Implants in the Supply Chain: ZBT Routers VulnCheck identifies three firmware implants in ZBT routers distributed globally: SPEAKINGSTONE, DARKLANTERN, and ENDLESSDOORS. DARKLANTERN provides unauthenticated root shell access via UDP port 9992. The implants were present in firmware before devices reached customers, representing a hardware-layer supply chain compromise.
  • ServiceNow, Gitea, and the CISA Observation Three maximum-severity vulnerabilities patched in ServiceNow AI Platform. Over 8,300 internet-exposed Gitea instances remain unpatched against actively exploited remote code execution flaws. CISA notes that most exploited vulnerabilities in 2026 should have been eradicated decades ago, citing organisational culture failures.
  • Closing Remarks The common thread across all threats is infrastructure inattention. Print servers, router firmware, and remote access tools that organisations do not actively monitor are precisely the surfaces attackers study most carefully. Practical guidance emphasises active management of unglamorous infrastructure.

Links

  • https://www.theregister.com/
  • https://www.papercut.com/
  • https://www.ncsc.gov.uk/
  • https://www.zscaler.com/blogs/security-research/
  • https://www.microsoft.com/
  • https://vulncheck.com/
  • https://www.servicenow.com/
  • https://www.shadowserver.org/
  • https://www.cisa.gov/
Comments0 Activity1 Chapters0 Transcript–
Threat Analysis : Cyber News for Small Business
Threat Analysis : Cyber News for Small Business @ThreatAnalysis Aug 28, 2026
17:36 Zero-Day Print Server Exploits, Teams Vishing, and Firmware Implants
Aug 28, 2026
Zero-Day Print Server Exploits, Teams Vishing, and Firmware Implants
0 0 0
RSS Podcast feed
HomeLinksCreditsMap

Powered by Castopod

Persons