Skip to content
Tech News
clear
Topics: Today This Week This Month This Year

Attackers exploit patched PaperCut flaws to steal data from print servers

Hackers are actively exploiting two recently disclosed PaperCut NG and MF vulnerabilities, CVE-2026-81578 and CVE-2026-82078, to bypass authentication and steal data from print management servers. PaperCut issued emergency fixes last week, but researchers at Defused say attackers are using the bypass to hijack the software's user-lookup function and dump database tables rather than pursue remote code execution as earlier reports suggested. Over 800 PaperCut servers remain exposed online according to Shadowserver, and PaperCut has not yet attributed the attacks or detailed post-compromise activity.

Guide details manual Ethernet cable method for fast local file transfers

A technical note explains how to move large files directly between two computers by connecting them with a standard Ethernet patch cable, manually assigning IPv6 addresses to each machine's interface, and piping data through tools like socat and dd. The author reports this setup can reach roughly 900 Mbits per second on ordinary hardware, translating to about 6.7 GB per minute, far outpacing USB drives or cloud uploads for nearby machines.

PaperCut issues second patch after first fix for exploited flaws was bypassed

PaperCut released a follow-up emergency update for PaperCut NG and MF after researchers found ways around its initial patch for actively exploited vulnerabilities. The company disclosed CVE-2026-82078, a critical unsafe dynamic class-loading bug, and CVE-2026-81578, a high-severity authentication bypass, which can be chained to let unauthenticated attackers execute code on vulnerable servers.

Critical flaw in GiveWP WordPress plugin enables remote code execution

Security researchers disclosed CVE-2026-82222, a maximum-severity vulnerability in the GiveWP donation plugin affecting versions through 4.16.7.1. By chaining an unauthenticated registration bypass, an insecure PHP unserialize function, and a gadget chain in bundled libraries, attackers can create an account, plant a malicious object in the plugin's session data, and trigger arbitrary command execution on the server by simply loading a front-end page.

Modders port leaked DLSS 5 Neural Rendering to RTX 4000 GPUs

A day after DLSS 5's nvngx_dlssnr.dll leaked via an early NBA 2K27 build and was ported into Control, modder Uncle Burrito patched the file so it runs on Ada Lovelace RTX 4080 cards instead of only Blackwell RTX 5000 GPUs. The fix works by identifying CUDA binaries incompatible with older hardware and replacing them with Ada-compatible versions, since the underlying FP8 AI model itself can already run on prior-gen chips. Tom's Hardware confirmed the patch functions on an RTX 4080, and more variations are reportedly being developed.

PaperCut Confirms Active Zero-Day Attacks on NG and MF Print Software

PaperCut has disclosed that hackers are actively exploiting an unpatched vulnerability affecting every version of its PaperCut NG and PaperCut MF print management software. The company confirmed real customer incidents, discovered the flaw after reproducing it with data from an affected university, and has since issued emergency patches for internet-facing servers.

Visa releases open-source AI tool that auto-patches vulnerabilities without human review by default

Visa has open-sourced the Vulnerability Agentic Harness, an 11-stage AI pipeline that detects security flaws, writes fixes, and adversarially tests its own patches in production code, with autonomous patching enabled by default unless an operator restricts it to detection only. The release comes alongside an expanded Visa Consulting & Analytics advisory practice and follows Visa's earlier work with Anthropic's Claude models under Project Glasswing.

CISA gives federal agencies until Saturday to patch Citrix NetScaler flaw CVE-2026-8452

CISA has added CVE-2026-8452, a memory overflow bug in Citrix NetScaler ADC and Gateway appliances, to its Known Exploited Vulnerabilities catalog, requiring federal civilian agencies to patch by August 29. Originally described by Citrix as only enabling denial-of-service, researchers at watchTowr later demonstrated it can be exploited for root-level remote code execution, and reports indicate attackers are already deploying web shells on unpatched systems.

GPT 5.6-Cyber breaks out of QEMU/KVM sandbox three times using zero-days

A tester given preview access to GPT-5.6-Cyber challenged the AI agent to escape a QEMU/KVM virtual machine on a Debian Linux host. The model succeeded three separate times, first using recently disclosed kernel bugs, then unpatched vulnerabilities not yet flagged as security issues, and finally by discovering its own zero-day exploits after the system was rebuilt from the latest source code.

Ubiquiti fixes three critical flaws in UniFi Protect, Talk and OS platforms

Ubiquiti released patches for three maximum-severity vulnerabilities affecting UniFi Protect, UniFi Talk, and UniFi OS Server products. The flaws include an input validation bug in Protect, a CRLF injection issue in UniFi OS that allows authentication bypass, and a command injection vulnerability in the Talk VoIP application, all exploitable remotely without authentication or user interaction.

Microsoft's August 2026 .NET update breaks printing and PDF export in WPF apps

Microsoft has confirmed that the August 2026 .NET Framework cumulative update causes some WPF-based applications to throw a System.IO.FileFormatException when printing or exporting to PDF/XPS with fonts like Calibri. The bug affects current Windows 10 and 11 releases as well as Windows Server versions from 2012 through 2025, and Microsoft is still working on a permanent fix.

Today's top topics: openai apple anthropic artificial intelligence qualcomm claude opus 5.5 iphone 18 pro ai safety motorola signature 27 sam altman
View all today's topics →