PaperCut is under active exploitation, with researchers and vendors tracking multiple remotely reachable issues now assigned CVE-2026-82078 and CVE-2026-81578. Reports indicate PaperCut released a second emergency patch after evidence emerged that the first fix could be bypassed, underscoring how quickly attackers iterate once a flaw is in the wild. The key operational takeaway: prioritize patching immediately, verify exposure for internet-facing instances, and monitor for persistence or follow-on activity even after the initial update.
Source: Security Week
FulcrumSec claims 86GB stolen from Manchester Airports Group via exposed API credentials
An extortion group calling itself FulcrumSec alleges it exfiltrated more than 80GB of data from Manchester Airports Group, pointing to leaked API credentials found in exposed client-side JavaScript. While claims should be treated cautiously until verified, the pattern is familiar: misconfigured web assets and over-permissive APIs can turn a single credential leak into widespread data exposure. Organizations should review front-end code for secrets, enforce strict API auth, and implement server-side authorization checks that limit what any stolen token can do.
Source: Security Affairs
Ransomware negotiations fail as Rhysida claims data theft exceeding 5TB
In a separate extortion case, the Rhysida ransomware group claims it exfiltrated over 5TB of data, including personal information and credentials, from Berlin. The reporting highlights a common “double pressure” dynamic in ransomware operations: even when victims decline ransom payments, threat actors may escalate by threatening or executing public leaks. Defenders should assume exfiltrated credentials may be used immediately (or sold), and they should accelerate credential resets, key rotation, and access reviews for impacted systems.
Source: Security Week
GiveWP critical flaw enables unauthenticated command execution on WordPress servers—patch now
Patchstack reports a critical vulnerability in GiveWP (WordPress donation plugin) that allows unauthenticated attackers to execute server commands by abusing a PHP object injection chain. Versions prior to the fixed release remain at risk, and “unauthenticated” materially increases attack probability because exploitation doesn’t require valid user access. WordPress teams should patch immediately and review logs for signs of exploitation, especially on sites exposed to the public internet.
Source: Security Affairs
Anthropic-related warning: session hijacking malware targets active Claude logins
Anthropic has issued warnings that infostealer malware can steal active Claude session cookies, enabling attackers to impersonate users without needing credentials. This is a reminder that modern account compromise doesn’t always require phishing for passwords—session theft can bypass MFA in practice if tokens remain valid. Users and enterprises should harden endpoints (browser security, detections for stealers), shorten session lifetimes where possible, and ensure suspicious session activity triggers rapid account/session revocation.
Source: SocRadar
Debian rejects an LLM “ban,” opting for voluntary disclosure of AI assistance
Debian developers voted against a proposed LLM ban and instead favored a policy that encourages contributors to disclose AI assistance but keeps disclosure voluntary beyond that. The decision reflects the practical challenge of enforcing provenance in code reviews when diffs can’t reliably indicate whether a human or model authored them. Security teams relying on Debian packages should treat this as governance news: transparency practices may improve, but supply-chain trust still depends on rigorous review, reproducible builds where possible, and careful patch validation.
Source: Help Net Security
Fire Ant expands beyond VMware: Cisco router and TACACS compromises reported
Sygnia reports that a China-nexus actor tracked as Fire Ant broadened its campaign from VMware hypervisors to compromise Cisco IOS XR routers, TACACS servers, and Linux management hosts used for authentication and network control. Targeting network-adjacent systems is strategically significant because it can enable credential theft and log interference, potentially blinding defenders while attackers maintain long-term access. Organizations should validate management-plane hardening, audit TACACS and router configurations, and review auth logs for anomalies that might indicate tampering or credential harvesting.
Source: The Hacker News
You May Also Be Interested In...
YARA-X 1.20.0 release adds improvements and bugfixes
AI AppSec tools agree on only 5% of security findings—what that means for triage
TerminalFix uses fake Cloudflare CAPTCHAs to deliver a reverse-tunnel backdoor