📡 Tech & Security Digest — 2026-08-29
Curated from Hacker News, security blogs, and tech publications.
BleepingComputer
- PaperCut warns of NG, MF flaw exploited in zero-day attacks — PaperCut is warning that hackers are actively exploiting a vulnerability in all versions of its PaperCut NG and PaperCut MF print management software …
- PaperCut releases second emergency patch for exploited flaws — PaperCut has released a second emergency security update for two actively exploited vulnerabilities in its PaperCut NG and MF print management softwar…
- Over 8,300 Gitea servers vulnerable to code execution attacks — Over 8,300 Internet-exposed Gitea instances are still unpatched against a critical security flaw exploited in ongoing remote code execution attacks, a…
- ServiceNow warns of three max severity security vulnerabilities — ServiceNow released security patches for three new maximum-severity AI Platform vulnerabilities that can be exploited in code injection, SQL injection…
- McKesson discloses breach after ShinyHunters claims patient data theft — Healthcare and pharmaceutical distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applicat…
Hacker News
- Just the rumour of a bug is enough to find an exploit these days (337 pts)
- EasyEffects can improve laptop speaker sound quality (166 pts)
- Review: Chuwi’s $449 Unibook laptop is a funhouse-mirror MacBook Neo (46 pts)
The Hacker News
- OpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Face — OpenAI on Wednesday revealed that reward hacking was a key driver behind the artificial intelligence (AI)-powered hack of Hugging Face last month, add…
- Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication — Malicious actors are exploiting a newly patched security flaw in PaperCut NG and MF to execute arbitrary code on susceptible instances, as the company…
- Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation efforts targeting a recently patched critica…
- 24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages — Cybersecurity researchers have disclosed details of a new campaign that uses a cluster of 24 npm packages as free phishing infrastructure for redirect…
- Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server — cPanel has released patches for a security flaw affecting domain parking and addon domain functionality in cPanel and WebHost Manager (WHM), which cou…
- PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions — PaperCut has alerted customers that bad actors are actively exploiting a vulnerability impacting all versions of its PaperCut NG and PaperCut MF print…
- Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE — Credit: Hacktron Vercel has released security patches for two critical-severity vulnerabilities in the Next.js web framework, both of which allow…
- NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions — Cybersecurity researchers have disclosed details of a new adversary-in-the-middle (AitM) phishing toolkit called NovaCookies that’s used as a proxy to…
- Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler — Cybersecurity researchers have discovered additional infrastructure and previously undocumented malware associated with Nimbus Manticore, an Iranian s…
- Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Ora…