September 12, 2026
- An inference-time activation edit sharply changed DeepSeek V4.1-Flash’s cyber and refusal results without rewriting weights. @0x0SojalSec subtracted a refusal direction at each layer and reported results moving from 4/32 to 24/32 on one refusal set and 5/32 to 31/32 on a 32-item cyber set. It requires local weights and a modified vLLM path, so this is not a remote jailbreak. The small, self-reported evaluation also does not establish parity with closed frontier models (earlier coverage).
· AI & Agent Security
- GitLab CVE-2026-85706 is now confirmed exploited, not merely scanned. CERT-SE says CISA added the CVSS 10.0 path-traversal flaw to KEV; an unauthenticated attacker can read arbitrary server-side files from vulnerable CE and EE instances. Fixed release lines are 19.1.8, 19.2.6, and 19.3.2, and a public PoC is available. Patch and examine logs from exposed servers (earlier coverage).
· Vulnerabilities & Active Exploitation
- PaperCut replaced its emergency fixes with fully tested maintenance releases. Versions 26.0.5, 25.0.13, and 24.1.10 supersede Emergency Patch Releases 1–3 for actively exploited CVE-2026-81578 and CVE-2026-82078, adding further hardening, The Hacker News reports. Customers on emergency builds should move to the maintenance releases (earlier coverage).
· Vulnerabilities & Active Exploitation
in Researchers Tie OpenAI’s Agent Swarm to a 2,000-Package RubyGems Attack
September 11, 2026
- GreyNoise traced the PaperCut NG/MF campaign (CVE-2026-81578, CVE-2026-82078) to
45.142.193.132, an IP it has watched since early July hitting Palo Alto, Ubiquiti, Citrix, SonicWall and Proxmox gear. Starting 31 August the actor built a lab with a vulnerable PaperCut server and an Active Directory box, built target lists via a Netlas.io API key, then ran hundreds of agents on an OpenAI Codex harness driving a DeepSeek model plus off-the-shelf offensive tooling. From empty workspace to RCE on a real victim took under four hours, first domain admin another two; once launched, 11 organizations fell in 26 seconds, and one US high school went from initial access to domain admin in seven minutes. PaperCut NG/MF runs as SYSTEM by default on Windows and is usually domain-joined (GreyNoise, BleepingComputer). Blackpoint Cyber reported the activity independently (The Hacker News). Attackers chaining the PaperCut pair for credential theft was earlier coverage; the AI orchestration and victim count are new.
· Offensive AI in the Wild
in Four Hours to First Victim: AI Agents Ran a Global PaperCut Campaign
September 6, 2026
- Attackers are chaining PaperCut authentication bypass and RCE flaws to steal credentials. Arctic Wolf observed CVE-2026-81578 and CVE-2026-82078 being used for command execution, reconnaissance and credential theft at schools and universities in the US and Europe. The Hacker News provides the new campaign-level detail following the earlier exploitation warning (earlier coverage).
· Vulnerabilities & Exploits
in One Loophole, 100 Agents, 27 Minutes
September 2, 2026
- PaperCut NG/MF exploitation has escalated from initial access to data theft. CVE-2026-81578 and CVE-2026-82078 chain to pre-auth RCE across all versions, and CISA is now warning on both (BleepingComputer, Horizon3) (earlier coverage).
· Exploited in the Wild
- Claude Code for n-day reversing — a practical walkthrough of driving an LLM through patch-diff-to-exploit on PaperCut NG, worth reading as a methodology piece regardless of the target (TechAnarchy).
· New Tools & Releases
in OpenAI Says Astra Crossed the Line: Autonomous Zero-Day Discovery at "Critical" Cyber Risk
September 1, 2026
JFrog Artifactory authentication bypass CVE-2026-82329 is actively exploited in the wild to mint admin tokens on build infrastructure, granting artifact-poisoning access to critical supply chains. A Metasploit module for PaperCut zero-days CVE-2026-81578 and CVE-2026-82078 is now public, narrowing the exposure window as roughly 1,000 instances remain vulnerable. Virtualizor VPS management platform was compromised via BGP hijack, affecting hundreds of hosting providers and their customer hypervisors and virtual servers. Anthropic is force-logging Claude users and removing payment data after commodity infostealers (Vidar, Lumma, StealC) harvested authenticated sessions for credential replay and usage fraud.
August 31, 2026
in Fully Patched, Still Domain Admin
August 29, 2026
- PaperCut NG/MF exploitation is live and the fixes are incomplete. The two flaws are now tracked as CVE-2026-81578 and CVE-2026-82078, and attackers are chaining them for unauthenticated code execution — the bug "gives an unauthenticated attacker remote control over PaperCut's trusted configuration, which could be used to execute arbitrary Java code inside the application" (The Hacker News). A second emergency patch has since shipped (BleepingComputer), and @watchtowrcyber, which is working with the vendor on the bypasses, tells users to "treat this as a trigger for incident response" and keep monitoring (earlier coverage).
· Vulnerabilities & Exploits
in PaperCut Ships a Second Emergency Patch After Researchers Bypass the First
August 28, 2026
- PaperCut NG/MF has an actively exploited zero-day. Huntress observed in-the-wild exploitation and reproduced a pre-auth RCE chain against a stock PaperCut NG 25.0.11.75758 install; PaperCut confirms an unauthenticated attacker can remotely alter trusted application configuration and execute arbitrary Java inside the app (BleepingComputer, Huntress). Emergency fixes exist for v25 and v26; v24 fixes are still in progress — pull application servers off the public internet now.
· Exploitation & Vulnerabilities
in Australia Charges Two Over the TeamPCP Supply-Chain Spree