📡 Tech & Security Digest — 2026-08-31
Curated from Hacker News, security blogs, and tech publications.
BleepingComputer
- PaperCut releases second emergency patch for exploited flaws — PaperCut has released a second emergency security update for two actively exploited vulnerabilities in its PaperCut NG and MF print management softwar…
- Over 8,300 Gitea servers vulnerable to code execution attacks — Over 8,300 Internet-exposed Gitea instances are still unpatched against a critical security flaw exploited in ongoing remote code execution attacks, a…
- McKesson discloses breach after ShinyHunters claims patient data theft — Healthcare and pharmaceutical distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applicat…
Hacker News
- Berlin is being blackmailed by hackers (52 pts)
- Hacking IKEA Furniture (330 pts)
- Transfer files over an Ethernet patch cable (109 pts)
- European Commission Revives Push for Encryption Backdoors in ProtectEU Strategy (431 pts)
- METR and Redwood Offer Holy %^ Postmortem of the HuggingFace Hack (256 pts)
Krebs on Security
- Two Alleged ‘TeamPCP’ Hackers Arrested in Australia — Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrati…
The Hacker News
- OpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Face — OpenAI on Wednesday revealed that reward hacking was a key driver behind the artificial intelligence (AI)-powered hack of Hugging Face last month, add…
- Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication — Malicious actors are exploiting a newly patched security flaw in PaperCut NG and MF to execute arbitrary code on susceptible instances, as the company…
- Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation efforts targeting a recently patched critica…
- 24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages — Cybersecurity researchers have disclosed details of a new campaign that uses a cluster of 24 npm packages as free phishing infrastructure for redirect…
- Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server — cPanel has released patches for a security flaw affecting domain parking and addon domain functionality in cPanel and WebHost Manager (WHM), which cou…
- PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions — PaperCut has alerted customers that bad actors are actively exploiting a vulnerability impacting all versions of its PaperCut NG and PaperCut MF print…
- Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE — Credit: Hacktron Vercel has released security patches for two critical-severity vulnerabilities in the Next.js web framework, both of which allow…
- NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions — Cybersecurity researchers have disclosed details of a new adversary-in-the-middle (AitM) phishing toolkit called NovaCookies that’s used as a proxy to…
- Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler — Cybersecurity researchers have discovered additional infrastructure and previously undocumented malware associated with Nimbus Manticore, an Iranian s…
- Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Ora…