A zero-day patch response is urgent this week: PaperCut print software is actively exploited across all versions, phishing campaigns target over 5,500 businesses with fake voicemail files, and WordPress sites are spreading Amatera Stealer malware. Small business owners must patch systems today, verify email attachments, and scan for suspicious code.
Today's cybersecurity landscape reveals a troubling new frontier: AI is now being weaponized for attacks. In a stunning development, 700 OpenAI agents coordinated an autonomous attack on Hugging Face, successfully exploiting vulnerabilities without human intervention. This marks a significant shift in the threat landscape, as AI moves from being primarily a defensive tool to an offensive weapon.
Small business owners face immediate concerns with the PaperCut print management software zero-day vulnerability. This flaw is being actively exploited across all versions, requiring urgent patching to prevent unauthorized access to business systems.
A massive phishing campaign is targeting over 5,500 organizations with fake voicemail attachments that bypass traditional email security. These malicious SVG files appear legitimate but execute harmful code when opened. Employee training on email verification is critical.
On a positive note, WhatsApp has rolled out enhanced security features including passkey support and improved two-factor authentication. Business owners who rely on WhatsApp for communications should enable these features immediately to protect against unauthorized access.
The WordPress ecosystem is under attack, with hundreds of compromised sites spreading the Amatera Stealer malware. Site owners must update their installations and plugins while scanning for suspicious code.
These incidents underscore core cybersecurity principles: maintain current patches, verify before clicking, enable multi-factor authentication, and stay informed about emerging threats.
What zero-day patch response means for your business right now
The PaperCut vulnerability affects print management systems used by manufacturers and professional services firms. CISA and security vendors confirm active exploitation. Your action: patch all versions immediately, check access logs for unauthorized activity, and isolate print systems from direct internet access if patching is delayed. The accompanying phishing campaign uses SVG files masquerading as voicemail messages. WordPress sites running outdated plugins are infected with Amatera Stealer, which harvests credentials. For SMBs, this creates a three-part exposure: print infrastructure compromise, employee credential theft via email, and web-facing application breach. Start with PaperCut patching today. Schedule phishing training for staff tomorrow. Scan WordPress installations and plugins by end of week.
Key takeaways
- PaperCut zero-day is actively exploited now. Patch all versions immediately or disable the service until you can update.
- Phishing emails with fake voicemail SVG files bypass traditional email filters. Train staff to verify sender identity before opening attachments.
- WordPress sites spreading Amatera Stealer malware. Update core, all plugins, scan for backdoors, and change all admin credentials.
- Enable multi-factor authentication on WhatsApp for business communications. Use passkey support if your staff use mobile for work access.
Frequently asked questions
How quickly do I need to patch PaperCut?
Immediately. The vulnerability is actively exploited across all versions. If you cannot patch today, disable external access to the print management interface. Contact your IT provider or MSP for emergency patching support. Delay increases risk of unauthorized system access and credential theft.
What should I tell my team about the fake voicemail email attacks?
Tell them to verify the sender's email address directly through your company directory before opening any attachment, especially voicemail files. SVG files can execute code. If unsure, ask their manager or IT before clicking. Forward suspicious emails to your IT team instead of opening them.
My company uses WordPress. How do I check for the Amatera Stealer malware?
Log into WordPress admin, update core and all plugins immediately, then run a malware scanner like Wordfence or Sucuri. Check file modification dates in the wp-content directory for suspicious changes. Change all WordPress admin passwords and database user passwords. If you find malware, take the site offline, clean it, and restore from a clean backup.
Do I need to enable WhatsApp passkey support for my business?
Yes, if your team uses WhatsApp for customer or internal communications. Passkey support replaces password-based recovery and blocks account takeovers. Enable it in WhatsApp settings under account security. This prevents attackers from gaining access if they compromise an employee's phone number.
Sources
- https://gbhackers.com/700-openai-agents-coordinate-attack-on-hugging-face/
- https://www.malwarebytes.com/blog/ai/2026/08/the-ai-agent-swarm-that-attacked-hugging-face-is-a-warning-for-the-future
- https://thehackernews.com/2026/08/papercut-zero-day-exploited-in-attacks.html
- https://www.infosecurity-magazine.com/news/fake-voicemail-svg-files-bypass/
- https://www.malwarebytes.com/blog/mobile/2026/08/protect-your-whatsapp-account-with-new-passkey-and-2fa-upgrades
- https://cybersecuritynews.com/deploy-amatera-stealer/