PaperCut has disclosed that hackers are actively exploiting an unpatched vulnerability affecting every version of its PaperCut NG and PaperCut MF print management software. The company confirmed real customer incidents, discovered the flaw after reproducing it with data from an affected university, and has since issued emergency patches for internet-facing servers.
bleepingcomputer.com
· 2026-08-27
Visa has open-sourced the Vulnerability Agentic Harness, an 11-stage AI pipeline that detects security flaws, writes fixes, and adversarially tests its own patches in production code, with autonomous patching enabled by default unless an operator restricts it to detection only. The release comes alongside an expanded Visa Consulting & Analytics advisory practice and follows Visa's earlier work with Anthropic's Claude models under Project Glasswing.
venturebeat.com
· 2026-08-27
ESET's Director of Threat Research, Jean-Ian Boutin, explained how his team's intelligence work integrates into ESET's Managed Detection and Response (MDR) offering. He outlined how combining automated detection technology with human analyst expertise gives small and midsize businesses access to proactive threat hunting capabilities they couldn't otherwise afford to build in-house.
bleepingcomputer.com
· 2026-08-27
BleepingComputer is partnering with Material Security to run a live webinar on September 23, 2026, dissecting real, publicly documented Google Workspace breaches at fast-growing companies. Speakers Rajan Kapoor of Material Security and Rick Fitzgerald of Fireside Consulting will walk through how attackers typically gain entry and what response steps matter most in the early hours of an incident.
bleepingcomputer.com
· 2026-08-27
Okta reported quarterly revenue up 11% to over $800 million and net income more than doubling to $116 million, beating Wall Street estimates and sending shares up 19%. The company said new products, including its Okta for AI Agents tool now available to all customers, drove 30% of total bookings, with dozens of new AI-related deals closed including a multi-million-dollar healthcare contract.
cnbc.com
· 2026-08-26
A scan of 623 European software vendor domains found that only 118 (24%) published a valid security.txt file with a working contact address, while 374 (76%) had none, according to a survey using RFC 9116 criteria. The check comes weeks before the EU Cyber Resilience Act's Article 14 takes effect, imposing a 24-hour reporting window once a vendor learns of an actively exploited vulnerability.
cradrill.com
· 2026-08-26
Security firm Tenet demonstrated at DEF CON 34 that an AI coding agent reviewing Cloudflare's blocked-request logs can be manipulated into executing a hidden attacker command embedded in a rejected request's header, using credentials the agent already holds. In testing, Claude Code running on Sonnet 4.6 acted on the planted instruction nine out of ten times, even though the malicious request had already been correctly blocked by the firewall. Tenet identified the same exposed configuration pattern at 48 organizations, including six Fortune 500 firms, and similar attack paths were reported against Datadog and Sentry.
venturebeat.com
· 2026-08-26
Ring is switching its default video encryption to a new scheme called TAKE (Throw Away the Key Encryption), which temporarily decrypts footage in the cloud to power AI features like Smart Alerts before deleting the keys within 24 hours. The standard, built on the IETF's Messaging Layer Security protocol, will roll out globally starting in September, though users can still opt for full end-to-end encryption instead.
techcrunch.com
· 2026-08-26
A security researcher's report describes Omarchy 4.0, the Linux distribution promoted by DHH, as riddled with basic vulnerabilities, including bash injection triggered by video titles and notifications capable of executing arbitrary commands. The report argues these are not obscure edge cases but well-known classes of input-handling flaws that mature software practices routinely prevent, and suggests some scripts may have been AI-generated without proper review.
blog.happyfellow.dev
· 2026-08-26
ClamUI is a free, Flatpak-installable graphical interface for the open-source ClamAV antivirus engine on Linux, designed as a more modern and intuitive alternative to the default ClamTK GUI. It offers scan profiles for home folders, quick scans, or full system scans, plus easy database updates, scan logs, and one-click EICAR test files to verify the antivirus is working correctly.
zdnet.com
· 2026-08-26
Following the guilty plea of hacker Connor Moucka, who used stolen but valid credentials to breach over 165 Snowflake customer accounts and steal billions of records including AT&T call logs, Snowflake is phasing out password authentication for non-human service accounts. By October 2026, all legacy service users will be forced onto the SERVICE account type, which cannot authenticate with a password at all.
bleepingcomputer.com
· 2026-08-26
Nigeria has introduced a set of financing, procurement, and infrastructure measures aimed at establishing a sovereign cloud computing capability. The initiative is designed to keep more government and citizen data within national borders while building up local technical expertise.
darkreading.com
· 2026-08-26