LIVE · cybersecurity feed
Live wire
CVE-2026-76581 · Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCECVE-2026-76639 · Hack One Robot, Reach the Next: Unitree G1 Security FlawsRhysida Ransomware Group Targets Berlin Government Ahead of VoteThe Cybersecurity Apocalypse Is Coming in ‘Months,’ AI Giants WarnCVE-2023-49105 · Philippine Nuclear and Naval Targets Hit by Suspected Chinese OperatorTerminalFix campaign deploys a reverse tunnel through multistage intrusionPerturbation Probing: A New Diagnostic for the Fragility of LLM SafetyResearcher shows how Claude Code can be tricked simply by asking it to summarize a websiteCosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was VulnerableATF confirms cyberattack hit system containing info on its investigation targets
vulnerability

Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication

Malicious actors are exploiting a newly patched security flaw in PaperCut NG and MF to execute arbitrary code on susceptible instances, as the company released a fresh emergency fix with additional hardening. "This vulnerability gives an unauthenticated attacker remote control over PaperCut's trusted configuration, which could be used to execute arbitrary Java code inside the application's

zeroday.news ·

Reports indicate that attackers are actively chaining two distinct security vulnerabilities in PaperCut NG and MF to achieve unauthenticated remote code execution on vulnerable systems. The vendor has released an emergency patch to address the newly exploited flaw, which includes additional hardening measures. This attack chain reportedly allows an unauthenticated attacker to gain remote control over PaperCut's trusted configuration, potentially enabling the execution of arbitrary Java code within the application.

The core of the reported attack appears to leverage a newly patched vulnerability that grants an unauthenticated attacker control over PaperCut's trusted configuration. This level of control is significant, as it could be manipulated to inject and execute arbitrary Java code directly within the application's environment. While the specifics of the initial flaw that enables this configuration manipulation are not detailed, it is presented as a critical entry point for the subsequent code execution.

The second part of the chain likely exploits the ability to execute arbitrary Java code. This is a powerful primitive, as Java applications often run with significant privileges, especially in server-side deployments like PaperCut NG and MF. Successful exploitation could lead to full system compromise, data exfiltration, or the establishment of persistent backdoors on the affected server.

PaperCut NG and MF are widely used print management software solutions, often deployed in enterprise and educational environments to manage printing, copying, and scanning. Products in this category typically handle sensitive user and network information, making them attractive targets for attackers. The broad deployment of such solutions means that a critical vulnerability like this could have a significant impact across various organizations.

Mitigation for this class of vulnerability typically involves applying vendor-provided patches immediately. Organizations are strongly advised to update their PaperCut NG and MF instances to the latest patched versions as soon as possible. Beyond patching, network segmentation, least privilege principles for application accounts, and robust intrusion detection systems can help limit the impact of successful exploitation. Regular security audits and vulnerability scanning are also crucial for identifying and addressing potential weaknesses before they are exploited.

The active exploitation of chained vulnerabilities highlights a persistent challenge in software security, where multiple seemingly less critical flaws can be combined to achieve a severe outcome. This incident underscores the importance of comprehensive security updates and proactive vulnerability management for critical infrastructure software. Organizations must remain vigilant and prioritize the timely application of security patches to defend against evolving threats that leverage complex attack chains.

vulnerabilitypatchcloud
ShareXLinkedInWhatsAppFacebook

More News

view all →
CVE-2026-76581critical

Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE

Multiple critical security flaws have been disclosed in WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP, that could lead to authentication bypass, account takeover, and arbitrary code execution. The vulnerabilities, according to Wordfence and Patchstack, are listed below - CVE-2026-76581 (CVSS score: 9.8) - An authentication bypass flaw in

CVE-2026-76639high

Hack One Robot, Reach the Next: Unitree G1 Security Flaws

A security researcher has discovered a chain of two vulnerabilities in the Unitree G1 humanoid robot that allows for remote, unauthenticated root access. The flaws can be exploited through a combination of Bluetooth, Unitree's cloud infrastructure, and the mobile app, enabling an attacker to compromise a robot and then use it to attack other nearby robots. Unitree has since patched the cloud vulnerability and issued bounties for the discovered flaws.

ai

[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI

ai

[Virtual Event] Building a Secure AI Strategy for the Enterprise

security

Anthropic is cutting Claude Code's current weekly limits by 17%

Anthropic is permanently increasing Claude Code's standard weekly usage limits by 25% for Pro, Max, Team, and seat-based Enterprise plans, but it's not as good as it sounds. [...]

security

Brave browser adds email aliases to help users evade tracking

The latest version of the Brave browser, 1.94, introduces a feature called 'Email Aliases' that allows users to generate disposable email addresses when signing up to a new service. [...]