📡 Tech & Security Digest — 2026-08-28
Curated from Hacker News, security blogs, and tech publications.
BleepingComputer
- PaperCut warns of NG, MF flaw exploited in zero-day attacks — PaperCut is warning that hackers are actively exploiting a vulnerability in all versions of its PaperCut NG and PaperCut MF print management software …
- Over 8,300 Gitea servers vulnerable to code execution attacks — Over 8,300 Internet-exposed Gitea instances are still unpatched against a critical security flaw exploited in ongoing remote code execution attacks, a…
- ServiceNow warns of three max severity security vulnerabilities — ServiceNow released security patches for three new maximum-severity AI Platform vulnerabilities that can be exploited in code injection, SQL injection…
- Webinar: How Google Workspace breaches happen and what to do next — Google Workspace breaches can begin with social engineering or forgotten third-party integrations rather than sophisticated exploits. This webinar exa…
- Manchester Airports Group says hackers stole travelers’ data — The Manchester Airports Group (MAG) disclosed that hackers breached its systems and stole customer data, including Wi-Fi sign-ups from Manchester, Sta…
- Australia arrests alleged TeamPCP hackers behind supply-chain attacks — Australian authorities have arrested and charged two young men accused of being part of the TeamPCP hacking group linked to a string of far-reaching d…
Hacker News
- Just the rumour of a bug is enough to find an exploit these days (118 pts)
- I used AWS cognito for a startup. I wouldn’t do it again (147 pts)
The Hacker News
- OpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Face — OpenAI on Wednesday revealed that reward hacking was a key driver behind the artificial intelligence (AI)-powered hack of Hugging Face last month, add…
- Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication — Malicious actors are exploiting a newly patched security flaw in PaperCut NG and MF to execute arbitrary code on susceptible instances, as the company…
- Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation efforts targeting a recently patched critica…
- 24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages — Cybersecurity researchers have disclosed details of a new campaign that uses a cluster of 24 npm packages as free phishing infrastructure for redirect…
- Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server — cPanel has released patches for a security flaw affecting domain parking and addon domain functionality in cPanel and WebHost Manager (WHM), which cou…
- PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions — PaperCut has alerted customers that bad actors are actively exploiting a vulnerability impacting all versions of its PaperCut NG and PaperCut MF print…
- Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE — Credit: Hacktron Vercel has released security patches for two critical-severity vulnerabilities in the Next.js web framework, both of which allow…
- NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions — Cybersecurity researchers have disclosed details of a new adversary-in-the-middle (AitM) phishing toolkit called NovaCookies that’s used as a proxy to…
- Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler — Cybersecurity researchers have discovered additional infrastructure and previously undocumented malware associated with Nimbus Manticore, an Iranian s…
- Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Ora…