Visualização normal

Antes de ontemCybersecurity News
  • ✇Cybersecurity News
  • Proxmox VE 7 Auth Bypass: PoC Public, Exploited in the Wild Do Son
    A public PoC now targets a Proxmox VE authentication bypass in EOL 7.x releases, and the pre-auth flaw is exploited in the wild for root access. Related Posts: Critical Google Chrome Vulnerabilities Patched in New Update CVE-2026-80047: Hugging Face Transformers Library Vulnerability CVE-2026-68162: Linux Kernel Root Escalation PoC Public The post Proxmox VE 7 Auth Bypass: PoC Public, Exploited in the Wild appeared first on Daily CyberSecurity.
     
  • ✇Security Affairs
  • PaperCut Zero-Day Under Active Attack: Emergency Patch Released Pierluigi Paganini
    PaperCut warns that a zero-day in NG and MF is being exploited. The company already release emergency patches to address it. PaperCut Software warns that attackers are actively exploiting a zero-day in its NG and MF print management products. The flaw has no CVE yet, and the company has not released technical details. PaperCut issued emergency patches on Friday and urged customers to install them immediately. It also recommends disconnecting application servers from the internet and limi
     

PaperCut Zero-Day Under Active Attack: Emergency Patch Released

28 de Agosto de 2026, 06:43

PaperCut warns that a zero-day in NG and MF is being exploited. The company already release emergency patches to address it.

PaperCut Software warns that attackers are actively exploiting a zero-day in its NG and MF print management products. The flaw has no CVE yet, and the company has not released technical details.

PaperCut issued emergency patches on Friday and urged customers to install them immediately. It also recommends disconnecting application servers from the internet and limiting access to trusted IP addresses.

“If your PaperCut NG/MF Application Server is accessible from the public internet, immediately restrict web access to trusted IP addresses only (e.g. internal IP addresses).” states the advisory. “Use firewall rules, network access controls, or equivalent measures to ensure the PaperCut server’s web interfaces cannot be reached from untrusted internet addresses. Take this action now, even if you have not observed suspicious activity.”

The company confirmed incidents affecting customers and said its investigation is still underway.

“PaperCut Software security response team is investigating active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF.” reads the advisory. “We are aware of confirmed customer incidents and are treating this matter with the highest priority. Our investigation is ongoing. We will update this security bulletin as verified information becomes available, including indicators of compromise and remediation guidance.”

PaperCut has not yet disclosed details about the vulnerability, the attack method, or the attackers behind the campaign.

So far, the company has identified several indicators of compromise:

  • Intrusion-detection, endpoint-security, or network-monitoring tools may flag suspicious activity involving the PaperCut Application Server, especially activity linked to pc-app.exe.
  • Attackers may delete, truncate, or alter PaperCut server.log files to hide their activity.
  • The server.log file may contain these entries:
    • ERROR No suitable driver found for jdbc:no:x
    • ERROR DatabaseUtils - Database error looking up cardID: VALUES CAST

Users running PaperCut should check their systems for these signs of compromise.

In May 2023, Microsoft warned that Iran-linked APT groups were exploiting another flaw, tracked as CVE-2023-27350, in attacks against PaperCut MF/NG print management servers. The CVE-2023-27350 flaw is a PaperCut MF/NG Improper Access Control Vulnerability. PaperCut MF/NG contains an improper access control vulnerability within the SetupCompleted class that allows authentication bypass and code execution in the context of SYSTEM.

In April 2023, Microsoft linked the attacks exploiting the CVE-2023-27350 and CVE-2023-27351 vulnerabilities in print management software PaperCut to a financially motivated threat actor tracked as Lace Tempest (formerly DEV-0950). The group is known to be an affiliate of the Clop ransomware RaaS affiliate, it has been linked to GoAnywhere attacks and Raspberry Robin infection. Since April 13, 2023, Lace Tempest added the PaperCut exploits to its arsenal.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Zero-Day)

  • ✇Cybersecurity News
  • Projextor Malware Hides in Fake PDF and Recipe Apps Do Son
    G DATA details Projextor, an Electron malware hidden in working PDF and recipe apps that runs injected scripts and captures the desktop. Related Posts: Android Head Unit Malware Recruits Vehicles into Botnet Evooo1Bot Linux Botnet Employs SOCKS Relays and DDoS AmnesiaStealer macOS Infostealer Hacks Apple Devices The post Projextor Malware Hides in Fake PDF and Recipe Apps appeared first on Daily CyberSecurity.
     

77 Counterfeit Open VSX Extensions Collected Developer and CI/CD Data

10 de Agosto de 2026, 11:52

Security researchers found 150 lookalike Open VSX extensions published under trusted names, highlighting how extension marketplaces can expose developer credentials, source code, and CI/CD systems to supply-chain risk.

The post 77 Counterfeit Open VSX Extensions Collected Developer and CI/CD Data appeared first on TechRepublic.

Gmail’s New Feature Warns You Before Revealing You Were BCC’d

4 de Agosto de 2026, 13:26

Gmail now warns BCC recipients before they reply all, helping prevent accidental exposure of their involvement and email address.

The post Gmail’s New Feature Warns You Before Revealing You Were BCC’d appeared first on TechRepublic.

Top 7 Enterprise IT Asset Management Software for 2027

Compare 7 enterprise IT asset management platforms for 2027, covering security, automation, cost, compliance, lifecycle tracking and business requirements.

Cursor Quietly Patches High-Severity Git Vulnerability After Seven-Month Delay

28 de Julho de 2026, 14:15

Cursor has patched a high-severity Windows vulnerability that allowed malicious Git repositories to execute code, highlighting security risks in AI coding environments.

The post Cursor Quietly Patches High-Severity Git Vulnerability After Seven-Month Delay appeared first on TechRepublic.

Talos: Attackers Refine Phishing Playbook To Target Critical Infrastructure

28 de Julho de 2026, 16:30

Phishing played a part in more than half of all incident response engagements undertaken by Talos, Cisco's threat research organization, during the second quarter of 2026, with healthcare organizations and manufacturing firms among the top targets.

The post Talos: Attackers Refine Phishing Playbook To Target Critical Infrastructure appeared first on The Security Ledger with Paul F. Roberts.

❌
❌