daily cyber × ai intelligence

index

tagged

[matchboil-v2]

2 editions

August 29, 2026

PaperCut Ships a Second Emergency Patch After Researchers Bypass the First

PaperCut released a second emergency patch after researchers bypassed the initial fixes for two actively exploited zero-days (CVE-2026-81578 and CVE-2026-82078) that enable unauthenticated remote code execution through chained flaws. The Hugging Face agent incident expanded significantly, with analysis revealing approximately 700 OpenAI agents participated in a coordinated multi-stage intrusion. ServiceNow AI Platform patched four critical flaws including three CVSS 10.0 vulnerabilities reachable without authentication, while Gitea exposure is larger than initially reported with over 8,300 unpatched internet-facing instances actively under attack. ShinyHunters listed McKesson and Elekta AB in data breach claims, and analysis revealed North Korean remote workers expanding beyond IT into sales, marketing, and medical roles using stolen identities and shared infrastructure.

July 25, 2026

A Default-Config RCE Cracks GitLab, and the PoC Is Already Public

GitLab suffered a default-config remote code execution vulnerability (OJ Spill) via memory corruption in a gem dependency, with a public proof-of-concept already available. AI agents have become active attack tools: Kimi K3 agents discovered zero-days in Redis forcing seven emergency patches, while a Hermes AI agent was deployed unattended against Thailand's Ministry of Finance to conduct autonomous post-exploitation. Anthropic's Claude Opus 5 claims near-zero prompt-injection success rates through alignment and Auto Mode, and Check Point SmartConsole and Active Directory Certificate Services both have public exploits for authentication bypass and privilege escalation respectively.