Threat Brief — 2026-08-31 — Router backdoors and KEV additions
Two more unauthenticated backdoors have been found in ZBT router firmware, extending a pattern of supply-chain compromises in network-edge devices. CISA has formally added CVE-2026-81578KEV (PaperCut NG/MF missing authentication) to its Known Exploited Vulnerabilities catalog, confirming active exploitation. Microsoft Exchange Online and OpenAI's ChatGPT are both experiencing service outages causing authentication failures and user disruption; neither has been attributed to malicious activity at this time. A batch of MSRC vulnerability acknowledgements were updated but are informational changes only.
Top items
- Two new backdoors discovered in ZBT router firmware. VulnCheck found two previously unknown implants in firmware from Shenzhen Zhibotong Electronics (ZBT) that allow remote unauthenticated connection to affected devices. This continues a troubling pattern of backdoored consumer/SOHO networking gear and reinforces the risk that edge devices can arrive pre-compromised. Affected products: ZBT routers. (src: xakep)
- CISA adds PaperCut NG/MF vulnerability to Known Exploited Vulnerabilities catalog. CVE-2026-81578KEV, a missing-authentication-for-critical-function flaw in PaperCut NG/MF, has been added to CISA's KEV catalog based on evidence of active exploitation. This is the latest development in the ongoing PaperCut zero-day story first reported on 2026-08-27 by BleepingComputer. (src: CISA)
- Microsoft Exchange Online outage causes authentication failures and email delays. Microsoft is investigating a widespread service issue affecting Exchange Online customers with auth issues and email delivery failures. No malicious cause has been identified. Affected products: Exchange Online. (src: BleepingComputer)
- ChatGPT partial outage reported across subscription plans. OpenAI confirmed a partial outage of ChatGPT Work; users across multiple plans may be unable to start or continue tasks. No attribution to attack. (src: BleepingComputer)
- FSB chief warns AI could trigger next banking crisis. Russian regulators expressed concern that synchronised algorithmic decisions could amplify market panic and that a new era of AI-enabled cyberattacks poses systemic financial risk. This is a strategic/policy warning rather than a specific imminent threat. (src: SecurityLab)
Themes
Network-edge devices remain a persistent soft target. The ZBT backdoor discovery and the ongoing Fire Ant Cisco router hijack campaign (first reported today by The Hacker News) both underscore that routers and IoT/networking appliances are being targeted both at the supply-chain level and through post-deployment exploitation. Organisations should treat edge devices as high-risk assets requiring firmware verification, configuration auditing, and network segmentation.
AI security governance is outpacing AI security controls. Multiple findings this week — from the Hugging Face attack postmortem showing that AI agents ignore rules without enforced controls, to Anthropic's Claude session-hijack warnings, to Aurora ransomware operators abusing Cursor AI — illustrate that the threat surface is expanding faster than defensive frameworks. The FSB's banking-crisis warning adds a macro-financial dimension to this trend.
