📡 Tech & Security Digest — 2026-09-01
Curated from Hacker News, security blogs, and tech publications.
BleepingComputer
- Recently patched PaperCut zero-days used in data theft attacks — Two security vulnerabilities in the PaperCut NG and MF print management software, patched last week after being exploited as zero-days, are now being …
Hacker News
- I turned my security cameras into an automatic bird identification system (508 pts)
- I think the military commissary’s freezers were hacked (351 pts)
- Transfer files over an Ethernet patch cable (172 pts)
Krebs on Security
- Two Alleged ‘TeamPCP’ Hackers Arrested in Australia — Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrati…
- Microsoft Plugs Nearly 400 Security Holes — Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including on…
- Microsoft Patches a Record 570 Security Flaws — Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple…
- Felons, Fraudsters Flog Offensive Cybersecurity Startup — A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right co…
The Hacker News
- OpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Face — OpenAI on Wednesday revealed that reward hacking was a key driver behind the artificial intelligence (AI)-powered hack of Hugging Face last month, add…
- Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication — Malicious actors are exploiting a newly patched security flaw in PaperCut NG and MF to execute arbitrary code on susceptible instances, as the company…
- Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation efforts targeting a recently patched critica…
- Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server — cPanel has released patches for a security flaw affecting domain parking and addon domain functionality in cPanel and WebHost Manager (WHM), which cou…
- PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions — PaperCut has alerted customers that bad actors are actively exploiting a vulnerability impacting all versions of its PaperCut NG and PaperCut MF print…
- Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE — Credit: Hacktron Vercel has released security patches for two critical-severity vulnerabilities in the Next.js web framework, both of which allow…
- NovaCookies Campaigns Abuse Genuine Docusign Notifications to Steal Microsoft 365 Sessions — Cybersecurity researchers have disclosed details of a new adversary-in-the-middle (AitM) phishing toolkit called NovaCookies that’s used as a proxy to…
- Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler — Cybersecurity researchers have discovered additional infrastructure and previously undocumented malware associated with Nimbus Manticore, an Iranian s…
- Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity — Threat actors are exploiting two critical flaws impacting Langflow and Ruby on Rails, according to new findings from VulnCheck.
The vulnerabilities i…
- ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions — The threat actor known as Silver Fox has been observed distributing the ValleyRAT backdoor disguised as a signed Chinese adware application, running t…