Security news
Latest security news
Fri, 28 Aug 2026
- Fake Voicemail SVG Attachments Fuel Large-Scale Phishing Campaign
A large-scale phishing campaign used fake voicemail SVG attachments to bypass email defenses, targeting 5527 organizations with over 26,000 malicious messages
Infosecurity Magazine - The Vulnpocalypse Is Repricing the Bug Bounty Economy
The surge in AI-powered vulnerability reports is driving down bug bounty prices, and that could spell trouble for independent researchers.
Dark Reading - CISA: Most exploited vulnerabilities should have been eradicated decades agoHacker News2 outlets
- Industry that built the problem offers to sell you the solution
100+ tech giants warn AI attacks are coming, skip the part where they pay for defenses
The Register - Shai-Hulud hackers: two men charged over TeamPCP’s global supply chain crime spree that hit OpenAI, and thousands more
More than 1,000 organisations, 500,000 stolen credentials, and one self-propagating worm named after a Dune sandworm - two men now face charges over TeamPCP's global hacking spree. Read more in my article on the Hot for Security blog.
Graham Cluley - PaperCut NG/MF Critical Zero-Day Exploited in the Wild
Overview On August 27, 2026, PaperCut Software published an urgent security advisory stating that it is investigating active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF. PaperCut has confirmed customer incidents and is treating the issue as a security emergency. At the initial time of disclosure, the vulnerability had not been assigned a CVE identifier, and PaperCut had not publicly disclosed a CVSS score, vulnerability class, authentication requirements, or the technical details of the exploit path. However on August 28, the vendor assigned CVE-2026-81578 and CVE-2026-82078 for the two vulnerabilities that make up the exploit chain. CVE ID Description CWE CVSSv4 CVE-2026-81578 Authentication Bypass CWE-306 Missing authentication for critical function. 8.8 (High) CVE-2026-82078 Unsafe Dynamic Class Loading in Database Connector CWE-470 Use of Externally-Controlled input to select classes or code ('unsafe reflection'). 9.4 (Critical) PaperCut NG and PaperCut MF are print management platforms commonly deployed within enterprise, education, and other organizational environments. Because the PaperCut Application Server provides web-accessible administrative an
CriticalUsed in attacksRapid7 BlogPaperCut - Window to Tackle Surge in AI-Enabled Cyber Attacks Narrowing, Tech Giants Warn
More than 100 companies, including OpenAI, Anthropic, Google and Microsoft, have urged collective action to unlock the power of AI to protect critical public services
Infosecurity MagazineGoogle, Microsoft - Threat Actors Abuse Cursor Agent AI to Assist Ransomware Operations
Aurora ransomware operators are abusing SpaceX’s Cursor Agent AI tool to conduct tasks such as reconnaissance and exploitation activities
Infosecurity Magazine
Thu, 27 Aug 2026
- Chinese Routers Sold Worldwide Contain Backdoors
An untold number of ZBT routers sold around the world as white-label products come with several implants built by the manufacturer.
Dark Reading
About this news
- 1,371
- Stories
- 72
- Added in the last 24 hours
- 10
- Critical in the last 7 days
- 4
- Reported by several outlets