Security news

Latest security news

11 of 1,256 storiesPaperCutClear all

Mon, 14 Sept 2026

  1. ⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkits

    AI keeps showing up in the wrong places. Attackers are using it to speed up exploits, test defenses, and automate more of the job. Some models are also crossing lines on their own. That is not a great combination. The rest of the week is more familiar: old bugs still working, fresh exploit chains, exposed systems, weak defaults, and simple paths that should have been harder to abuse. A few of

    The Hacker NewsPaperCut

Fri, 11 Sept 2026

  1. Papercut AI Swarm Attack Heralds Changes for Cyber Kill Chain

    From creating lab environments for staging and testing agentic attacks to reconnaissance to lateral movement and exfiltration, the most innovative attackers are widely incorporating AI.

    Dark ReadingPaperCut
  2. Metasploit Wrap Up: This One Goes to Sixteen!

    This One Goes to Sixteen! Another banger from Metasploit with sixteen new modules, including ten exploit modules, with five on the CISA KEV list. Cisco, Papercut, Sonicwall, Jetbrains, and Langflow all have exploit modules, and not to be outdone, we even have a Metasploit scanner to watch the watchers! New module content (16) Elasticsearch ingest-attachment Apache Tika XFA XXE Local File Read Authors: Bourbon Offensive Security Services and Jean-Marie Bourbon Type: Auxiliary Pull request: #21739 contributed by kmkz Path: scanner/http/elasticsearch_tika_xfa_xxe CVE reference: CVE-2025-66516 Description: Adds an auxiliary scanner module for CVE-2025-54988/CVE-2025-66516. The module validates an XML External Entity (XXE) vulnerability in Apache Tika's XFA parser exposed through the Elasticsearch attachment ingest processor. SPIP Unauthenticated Blind SQLi via Date Field Escaping Bypass Authors: Benoit Hua, Franck Chevalier, Julien Voisin, and ka3n1x Type: Auxiliary Pull request: #21791 contributed by jvoisin Path: scanner/http/spip_annee_sqli Description: Adds modules/auxiliary/scanner/http/spip_annee_sqli.rb which exploits a blind SQL injection in SPIP's date column escaping logic. M

    Rapid7 BlogPaperCut, SonicWall, Cisco
  3. PaperCut Flaws Exploited in AI-Powered Attacks

    A Russian threat actor used AI to build, test, and deploy exploits against hundreds of organizations worldwide.

    SecurityWeekPaperCut
  4. PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws

    PaperCut on Thursday released a new security maintenance release that replaces all previously published emergency patches that were pushed to address two security flaws that have come under active exploitation. The software development company said PaperCut NG/MF versions 26.0.5, 25.0.13 and 24.1.10 are now available for customers to download. "These are Regular Maintenance Releases (MR) that

    The Hacker NewsPaperCut

Thu, 10 Sept 2026

  1. Hundreds of AI agents helped PaperCut attacker hit 395+ orgs, and some went off script

    Human operator: don't touch CIS orgs. AI agents: look a squirrel!

    The RegisterPaperCut
  2. AI-powered attack exploited PaperCut flaws to hack 395 organizations

    A threat actor, likely Russian-speaking, used hundreds of AI agents to develop and launch a global exploitation campaign targeting vulnerable PaperCut NG/MF servers.

    BleepingComputerPaperCut
  3. PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances

    A suspected Russian-speaking cyber actor has been attributed to the use of artificial intelligence (AI) to devise exploits targeting a recently disclosed pair of security flaws in PaperCut NG/MF and break into hundreds of instances. According to independent reports from Blackpoint Cyber and GreyNoise, the activity originates from "45.142.193[.]132," an IP address that has been linked to

    The Hacker NewsPaperCut

Sat, 5 Sept 2026

  1. Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities

    Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as

    CriticalUsed in attacksThe Hacker NewsPaperCut

Mon, 31 Aug 2026

  1. PaperCut security advisory (AV26-858) – Update 2

    Serial number: AV26-858 Date: August 28, 2026 Updated: August 31, 2026 As of August 27, 2026, PaperCut is affected by vulnerabilities in the following products: PaperCut MF Prior to v24 Emergency Patch Release 2 Prior to v25 Emergency Patch Release 2 Prior to v26 Emergency Patch Release 2 PaperCut NG Prior to v24 Emergency Patch Release 2 Prior to v25 Emergency Patch Release 2 Prior to v26 Emergency Patch Release 2 Update 1 Open-source reporting indicates that CVE-2026-81578 and CVE-2026-82078 are related to PaperCut MF and PaperCut NG are being exploited in the wild. Update 2 On August 31, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-81578 and CVE-2026-82078 to their Known Exploited Vulnerabilities (KEV) Database. The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available. URGENT Security Advisory: PaperCut NG/MF Security Bulletin (27 Aug 2026) CISA KEV: CVE-2026-81578 CISA KEV: CVE-2026-82078

    CriticalUsed in attacksCanadian Centre for Cyber SecurityPaperCut

About this news

1,256
Stories
41
Added in the last 24 hours
19
Critical in the last 7 days
4
Reported by several outlets