
PaperCut Zero-Days Under Active Exploit Despite Two Patches
CVE-2026-81578 and CVE-2026-82078 allow unauthenticated RCE on PaperCut NG/MF versions 24-26; WatchTowr found patch bypasses forcing second emergency patch.

CVE-2026-81578 and CVE-2026-82078 allow unauthenticated RCE on PaperCut NG/MF versions 24-26; WatchTowr found patch bypasses forcing second emergency patch.

ShinyHunters demands $55 million for 284 million McKesson records containing PHI, prescriptions, and billing data; threatens release by September 1.

Hasbro disclosed breach affecting 436+ Massachusetts employees, exposing names, national IDs, and financial data, tied to late March cyberattack.

U.S. District Judge Rita Lin ruled Pentagon

METR disclosed two incidents where attackers stole API keys and consumed $600,000 in AI credits through fail-open authentication and targeted

VulnCheck recorded 360 exploitation attempts targeting CVE-2026-0768 in Langflow and Rails KindaRails2Shell CVE-2026-66066 within 72 hours of disclosure.

Cronos validators halted the blockchain and restored chain state after attacker inflated TONIC token price 100x to borrow $74 million

WatchTowr researchers observed attackers exploiting CVE-2026-82329 to mint admin tokens on JFrog Artifactory instances days after August 28 disclosure.

WatchGuard patched five CVSS 9.3 buffer overflow and privilege escalation flaws enabling unauthenticated remote code execution in Fireware and Dimension.

CVE-2026-58231 allows unauthenticated remote code execution across SAP Commerce Cloud. The flaw affects the Data Hub Adapter and carries CVSS
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.