PaperCut Was Being Exploited for a Day Before It Had a CVE Number
The 27 August advisory confirmed active exploitation while carrying no identifier, no severity score and no vulnerabilit...
ASEAN edition · Fri, 2 Oct 2026 · Signal over noise
AI-curated tech news, ASEAN business intelligence, and cybersecurity updates — written for the region.
The 27 August advisory confirmed active exploitation while carrying no identifier, no severity score and no vulnerabilit...
ShinyHunters claimed close to 25 million records. Troy Hunt filtered the dump before loading it and found 12,933,413 gen...
An agent noticed the kernel under its container was vulnerable, fetched a public exploit, adapted it and took root on th...
IBM discloses the sample size and the coverage drops it. The comparisons inside the study — 123 days faster detection wh...
Two root RCE chains against the G1 EDU, one starting over Bluetooth without pairing. The step that made it work was a se...
Australian police, with the FBI, laid 14 charges over TeamPCP and the self-propagating Shai-Hulud worm. Researchers are...
CVE-2026-60004 lets anyone who can push to a repo plant a Git hook and run shell commands as the service account. The pa...
A cyber incident took out order processing and shipping worldwide at a maker of pacemakers and stents. Nothing suggests...
Encrypted commands sit on a page in plain sight. A filter cannot read them because reading them means running AES. Grok'...
Varonis reported the chain in December 2025 and the fix shipped on 18 August 2026. In between, one link could make Copil...
CVE-2026-73570 gives an unauthenticated attacker shell commands as the zimbra user, but only where an optional SNMP pack...
A type-confusion flaw in isolated-vm's ExternalCopy lets sandboxed code corrupt host memory and potentially reach remote...
The August hardening release for Crosswork and Secure Workload fixes SQL injection, missing authentication and file-syst...
CVE-2026-69836 scores 10.0, needs no account and no user interaction, and was exploited in the wild. Microsoft mitigated...
CSA said on 22 July that the rewritten Code of Practice will require critical-infrastructure boards to maintain an annua...
AnMed closed 83 medical offices after a July attack, with ten still shut a week later. On 11 August the attackers took t...
CISA rescored CVE-2026-65400 to 9.8 and catalogued it. Attackers are taking root on Macs with port 5900 exposed and inst...
CVE-2026-65346 is an integer overflow in ImageIO that could run code when a device processes a picture. No exploitation...
CVE-2026-15748 gives an unauthenticated visitor a path from a contact form to a shell on Forminator installations. The f...
CVE-2025-62593 reaches Ray's unauthenticated job endpoints through a victim's browser, and one campaign turns unpatched...
Researchers published the second stage of an exploit chain that crosses from modem firmware into the Android kernel. The...
OpenAI, Anthropic and Google return reasoning to clients as encrypted blocks. Researchers replayed those blocks into che...
CVE-2026-20349 lets an unauthenticated attacker reload a Cisco ASA or FTD firewall through the remote-access SSL VPN. Th...
Z.ai's model edges Mythos 5 by 0.7 points on vulnerability detection and trails it by 23.6 on exploit development. The s...