daily cyber × ai intelligence

index

tagged

[papercut]

8 editions · 11 items

September 12, 2026

  • An inference-time activation edit sharply changed DeepSeek V4.1-Flash’s cyber and refusal results without rewriting weights. @0x0SojalSec subtracted a refusal direction at each layer and reported results moving from 4/32 to 24/32 on one refusal set and 5/32 to 31/32 on a 32-item cyber set. It requires local weights and a modified vLLM path, so this is not a remote jailbreak. The small, self-reported evaluation also does not establish parity with closed frontier models (earlier coverage). · AI & Agent Security
  • GitLab CVE-2026-85706 is now confirmed exploited, not merely scanned. CERT-SE says CISA added the CVSS 10.0 path-traversal flaw to KEV; an unauthenticated attacker can read arbitrary server-side files from vulnerable CE and EE instances. Fixed release lines are 19.1.8, 19.2.6, and 19.3.2, and a public PoC is available. Patch and examine logs from exposed servers (earlier coverage). · Vulnerabilities & Active Exploitation
  • PaperCut replaced its emergency fixes with fully tested maintenance releases. Versions 26.0.5, 25.0.13, and 24.1.10 supersede Emergency Patch Releases 1–3 for actively exploited CVE-2026-81578 and CVE-2026-82078, adding further hardening, The Hacker News reports. Customers on emergency builds should move to the maintenance releases (earlier coverage). · Vulnerabilities & Active Exploitation

in Researchers Tie OpenAI’s Agent Swarm to a 2,000-Package RubyGems Attack

September 11, 2026

  • GreyNoise traced the PaperCut NG/MF campaign (CVE-2026-81578, CVE-2026-82078) to 45.142.193.132, an IP it has watched since early July hitting Palo Alto, Ubiquiti, Citrix, SonicWall and Proxmox gear. Starting 31 August the actor built a lab with a vulnerable PaperCut server and an Active Directory box, built target lists via a Netlas.io API key, then ran hundreds of agents on an OpenAI Codex harness driving a DeepSeek model plus off-the-shelf offensive tooling. From empty workspace to RCE on a real victim took under four hours, first domain admin another two; once launched, 11 organizations fell in 26 seconds, and one US high school went from initial access to domain admin in seven minutes. PaperCut NG/MF runs as SYSTEM by default on Windows and is usually domain-joined (GreyNoise, BleepingComputer). Blackpoint Cyber reported the activity independently (The Hacker News). Attackers chaining the PaperCut pair for credential theft was earlier coverage; the AI orchestration and victim count are new. · Offensive AI in the Wild

in Four Hours to First Victim: AI Agents Ran a Global PaperCut Campaign

September 6, 2026

  • Attackers are chaining PaperCut authentication bypass and RCE flaws to steal credentials. Arctic Wolf observed CVE-2026-81578 and CVE-2026-82078 being used for command execution, reconnaissance and credential theft at schools and universities in the US and Europe. The Hacker News provides the new campaign-level detail following the earlier exploitation warning (earlier coverage). · Vulnerabilities & Exploits

in One Loophole, 100 Agents, 27 Minutes

September 2, 2026

  • PaperCut NG/MF exploitation has escalated from initial access to data theft. CVE-2026-81578 and CVE-2026-82078 chain to pre-auth RCE across all versions, and CISA is now warning on both (BleepingComputer, Horizon3) (earlier coverage). · Exploited in the Wild
  • Claude Code for n-day reversing — a practical walkthrough of driving an LLM through patch-diff-to-exploit on PaperCut NG, worth reading as a methodology piece regardless of the target (TechAnarchy). · New Tools & Releases

in OpenAI Says Astra Crossed the Line: Autonomous Zero-Day Discovery at "Critical" Cyber Risk

September 1, 2026

Attackers Are Living in the Management Plane

JFrog Artifactory authentication bypass CVE-2026-82329 is actively exploited in the wild to mint admin tokens on build infrastructure, granting artifact-poisoning access to critical supply chains. A Metasploit module for PaperCut zero-days CVE-2026-81578 and CVE-2026-82078 is now public, narrowing the exposure window as roughly 1,000 instances remain vulnerable. Virtualizor VPS management platform was compromised via BGP hijack, affecting hundreds of hosting providers and their customer hypervisors and virtual servers. Anthropic is force-logging Claude users and removing payment data after commodity infostealers (Vidar, Lumma, StealC) harvested authenticated sessions for credential replay and usage fraud.

August 31, 2026

  • A working RCE lab for GiveWP CVE-2026-82222 (CVSS 10) is now public, giving defenders and testers a reproducible target for the WordPress donation plugin flaw (GitHub) (earlier coverage). · New Tools & Releases
  • PaperCut exploitation is now a race against patch rates: scanning of exposed PaperCut NG/MF servers is under way and roughly 47% remain unpatched, following last week's emergency fixes for the actively exploited zero-day (Security Affairs) (earlier coverage). · Vulnerabilities & Exploits

in Fully Patched, Still Domain Admin

August 29, 2026

  • PaperCut NG/MF exploitation is live and the fixes are incomplete. The two flaws are now tracked as CVE-2026-81578 and CVE-2026-82078, and attackers are chaining them for unauthenticated code execution — the bug "gives an unauthenticated attacker remote control over PaperCut's trusted configuration, which could be used to execute arbitrary Java code inside the application" (The Hacker News). A second emergency patch has since shipped (BleepingComputer), and @watchtowrcyber, which is working with the vendor on the bypasses, tells users to "treat this as a trigger for incident response" and keep monitoring (earlier coverage). · Vulnerabilities & Exploits

in PaperCut Ships a Second Emergency Patch After Researchers Bypass the First

August 28, 2026

  • PaperCut NG/MF has an actively exploited zero-day. Huntress observed in-the-wild exploitation and reproduced a pre-auth RCE chain against a stock PaperCut NG 25.0.11.75758 install; PaperCut confirms an unauthenticated attacker can remotely alter trusted application configuration and execute arbitrary Java inside the app (BleepingComputer, Huntress). Emergency fixes exist for v25 and v26; v24 fixes are still in progress — pull application servers off the public internet now. · Exploitation & Vulnerabilities

in Australia Charges Two Over the TeamPCP Supply-Chain Spree