Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication
Attackers are chaining two vulnerabilities in PaperCut NG and MF to achieve unauthenticated remote code execution by compromising the application's trusted configuration. PaperCut has released an emergency patch with additional hardening measures to address the flaw. The vulnerability allows malicious actors to execute arbitrary Java code within the application without requiring authentication credentials.
New research reveals that AI safety refusal lives in a thin neural layer, highlighting the critical need for external, multi-layered security. The post Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety appeared first on Unit 42.
Cosmos Labs disclosed that a critical balance-handling vulnerability in its shared EVM module was actively exploited to drain funds from six blockchains over a five-day period in August 2026, despite the company's awareness that every blockchain using the module was vulnerable. The flaw, tracked as GHSA-7g4w-cg88-2cq2, was published without standard vulnerability identifiers or severity scoring, complicating threat assessment and response coordination across affected networks.
PaperCut disclosed an emergency advisory regarding active exploitation of vulnerabilities in its PaperCut NG and MF print management software platforms. The flaws are currently being leveraged by threat actors in real-world attacks, prompting immediate attention from organizations using these widely deployed solutions.
Adversaries are already harvesting encrypted data today through "harvest now, decrypt later" tactics, planning to decrypt it once quantum computers mature, making the quantum threat an immediate operational concern rather than a distant future problem. Organizations must establish comprehensive cryptographic inventories and execute a phased migration strategy to quantum-resistant algorithms, with regulatory mandates including Executive Order 14412 setting federal deadlines of 2030-2031 for transitioning to post-quantum cryptography. Without complete visibility into cryptographic assets across their environment, organizations cannot effectively prioritize and remediate quantum vulnerabilities before attackers can exploit them with future quantum capabilities.