Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication

A critical vulnerability in PaperCut, a popular print management software used by organizations worldwide, has been exploited by attackers to execute code without authentication. The chain of vulnerabilities allows hackers to gain elevated privileges and potentially take control of entire networks. This alarming development highlights the need for robust security measures and regular patching. The … Read more

Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable

A Critical Flaw in Cosmos EVM Exposes Thousands of Blockchain Networks A disturbing revelation has emerged about a long-known vulnerability in the Cosmos EVM (Ethereum Virtual Machine), which has been exploited by malicious actors despite warnings from its developers. The issue, first identified several months ago, affects not just one but thousands of blockchain networks … Read more

GiveWP WordPress donation plugin flaw lets hackers execute server commands

A Critical Flaw in GiveWP Plugin Exposes Hosting Servers to Hacker Attacks A serious vulnerability has been discovered in the popular GiveWP donation plugin for WordPress, allowing hackers to execute arbitrary commands on hosting servers with ease. This maximum-severity flaw, identified as CVE-2026-82222, affects all versions of the plugin up to 4.16.7.1 and can be … Read more

PaperCut releases second emergency patch for exploited flaws

Cybersecurity firm PaperCut has released a second emergency patch for two actively exploited vulnerabilities in its print management software, after researchers discovered multiple ways to bypass the initial fixes. The company had initially warned that hackers were exploiting a vulnerability in zero-day attacks against customer servers and released an emergency patch earlier this month. The … Read more

ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body

A Critical Vulnerability in ownCloud Exposes Sensitive Data from Philippine Research Institution A serious security flaw has been exploited by hackers to steal sensitive records, including nuclear-related documents, from a research organization in the Philippines. The vulnerability, affecting the popular file-sharing platform ownCloud, was used to compromise the institution’s systems and expose confidential information. This … Read more

Android 17 Adds OS-Wide ECH to Hide Website Visits From Network Providers

Android’s latest operating system update, version 17, has quietly introduced a new feature that significantly enhances user privacy. Dubbed “OS-Wide ECH” – short for Encrypted Client Hello – this innovation allows Android devices to conceal website visits from network providers and other entities that might be monitoring internet traffic. The way it works is relatively … Read more

Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication

Cybersecurity researchers have uncovered a sophisticated attack vector that exploits two previously unknown vulnerabilities in popular printing management software PaperCut. The attackers are chaining these flaws together to execute malicious code on affected systems without requiring user authentication, posing a significant threat to organizations worldwide. The vulnerability lies within PaperCut’s architecture, which allows for cross-domain … Read more

Toy-making giant Hasbro disclose data breach affecting employees

A Major Toy Maker Exposes Employee Data in Latest Cybersecurity Mishap Toy giant Hasbro has revealed that a group of attackers gained access to sensitive employee information, leaving a significant number of staff members vulnerable to identity theft and financial loss. The company, which owns beloved brands such as Monopoly, Nerf, and Transformers, filed data … Read more

Over 8,300 Gitea servers vulnerable to code execution attacks

Over 8,300 Gitea servers remain vulnerable to code execution attacks despite a critical security fix being available since July. Cybersecurity watchdog Shadowserver has identified nearly 8,400 Internet-exposed Gitea instances that are still unpatched against a serious flaw exploited in ongoing remote code execution attacks. The vulnerability, known as CVE-2026-60004, was reported by Salesforce researcher Shai … Read more

AI Is Accelerating Vulnerability Discovery. Can Defenders Keep Up?

As AI-powered vulnerability discovery tools accelerate the rate at which new vulnerabilities are identified, cybersecurity defenders are facing a daunting challenge: can they keep up with the sheer volume of threats? A recent update to the National Vulnerability Database (NVD) has introduced changes that prioritize newer vulnerabilities over older ones, but this shift comes with … Read more