A critical security alert reports two active exploits involving PaperCut NG/MF vulnerabilities (CVE-2026-82078 and CVE-2026-81578). Furthermore, a cyberespionage campaign attributed to the Dark Caracal group has targeted a telecommunications firm in Venezuela using a new malware framework called GoCaracal. The malware operates through sophisticated phishing methods and employs advanced techniques such as AES-GCM encryption and blockchain fallback mechanisms for command and control.
Detection measures recommended for organizations include strict email security, monitoring for suspicious processes, and network traffic analysis. The campaign is part of a larger trend of targeted intrusions across Latin America, with evidence pointing to compromised networks in multiple countries.