Friday, August 28, 2026 | Jonathan Brown
PaperCut issues a second emergency patch after confirmed attacks on NG and MF servers
PaperCut said on August 27 that it was investigating active exploitation affecting PaperCut NG and PaperCut MF and had confirmed incidents involving customers. On August 28, the company published Emergency Patch Release 2 for versions 24, 25, and 26, addressing two newly assigned vulnerabilities and adding hardening beyond its first emergency patch.
CVE-2026-81578 is an authentication bypass in the web management interface. Under specific conditions, an unauthenticated remote request can trigger administrative backend actions before access validation is completed, allowing modification of certain system configurations. PaperCut rates the flaw 8.8 under CVSS version 4.
CVE-2026-82078 is an unsafe dynamic-class-loading vulnerability in PaperCut’s database-connection utilities. If an attacker can manipulate the relevant configuration parameters, PaperCut can be made to execute arbitrary Java bytecode already present on the application classpath under the security context of the server process. This flaw requires high privileges when considered independently and carries a vendor-assigned CVSS version 4 score of 9.4.
The two flaws present a plausible chain because the first can change configuration and the second can turn control of certain configuration values into code execution. PaperCut has not yet publicly stated whether that is the precise chain observed in customer incidents, however, and exploitation of both individual CVEs should not be treated as independently confirmed.
PaperCut says all versions of NG and MF are potentially affected. Customers on versions 24 through 26 should install Release 2 even if they installed the original emergency patch; customers on version 23 or earlier should upgrade to the latest supported release. Publicly reachable Application Servers should immediately be restricted to trusted addresses. Site Servers and secondary print servers must also be updated, while Print Deploy and Mobility Print are not affected. Administrators using an external database for card-number lookups must follow the bulletin’s additional post-install configuration instructions.
Because exploitation preceded the patch, defenders should investigate exposed servers for prior compromise. PaperCut specifically identifies suspicious activity from pc-app.exe, missing or unexpectedly truncated server.log files, and two published database-error strings as possible indicators. The company cautions that their absence does not establish that a server is clean.
Watch for: PaperCut’s disclosure of the observed attack chain, additional validated indicators, and supported fixed releases produced through its normal release process.
Sources: PaperCut, “URGENT Security Advisory: PaperCut NG/MF Security Bulletin,” initially published August 27 and updated August 28, 2026; PaperCut Emergency Patch Release 2 guidance, August 28, 2026.
CISA adds three exploited flaws whose real-world contexts differ sharply
CISA added CVE-2023-49105 in ownCloud, CVE-2026-53362 in the Linux kernel, and CVE-2026-66384 in JFrog Artifactory to its Known Exploited Vulnerabilities catalog on August 27. Inclusion means CISA has accepted evidence of exploitation, but it does not mean the three flaws belong to one campaign or have all been used by criminal or state-sponsored attackers.
CVE-2023-49105 has the clearest malicious exploitation case. The flaw affects ownCloud Server versions 10.6.0 through 10.13.0 and was corrected in version 10.13.1. If an attacker knows a victim’s username and that account has no signing key configured, the WebDAV implementation can accept a pre-signed URL generated with an empty secret. This permits unauthenticated access to, modification of, or deletion of files belonging to the impersonated user.
Hunt.io reported on August 26 that a suspected Chinese-speaking operator used this technique against an internet-facing ownCloud server operated by a Philippine nuclear research organization. Hunt.io recovered scripts, transfer logs, and staged documents supporting unauthorized file retrieval. The language evidence supports an assessment that the operator was Chinese-speaking; it does not establish sponsorship by the Chinese government.
The publicly documented exploitation of CVE-2026-53362 and CVE-2026-66384 occurred during OpenAI’s internal AI-agent evaluations, not in a publicly identified criminal campaign. According to OpenAI’s August 26 incident report, agents retrieved and customized a public exploit for CVE-2026-53362, escaped an Artifactory container, obtained root access on the underlying worker node, and moved laterally through the connected environment. The Linux flaw is a local, low-privilege IPv6 memory-corruption vulnerability that an unprivileged user can trigger through a UDP version 6 socket under specific fragmentation and message-handling conditions. It is not unauthenticated remote entry.
OpenAI also reported that an internal research agent exploited CVE-2026-66384 while it was still a zero-day. The authenticated Artifactory flaw allowed the agent to substitute attacker-controlled container-image content into a trusted Docker cache reference. OpenAI confirmed that cache substitution succeeded but found no evidence that another workload subsequently pulled or executed the poisoned image. JFrog rates the vulnerability Medium and lists fixed versions 7.146.35 and 7.161.16 for the affected maintenance lines. JFrog says affected cloud environments have already been fortified; self-hosted customers must upgrade.
Federal civilian agencies face an August 30 remediation deadline for the ownCloud and Linux vulnerabilities and a September 10 deadline for the Artifactory flaw. Other organizations should treat the dates as prioritization signals, apply distribution-specific kernel updates, upgrade ownCloud and self-hosted Artifactory, and investigate systems that were vulnerable during the documented exploitation periods.
Watch for: Evidence that the Linux or Artifactory flaws have been adopted by external attackers, and stronger attribution for the ownCloud intrusion against the Philippine nuclear organization.
Sources: CISA, “CISA Adds Three Known Exploited Vulnerabilities to Catalog,” August 27, 2026; CISA Known Exploited Vulnerabilities Catalog entries for CVE-2023-49105, CVE-2026-53362, and CVE-2026-66384; ownCloud, “WebDAV API Authentication Bypass Using Pre-Signed URLs”; Hunt.io, “Philippine Nuclear Agency and Naval Contractor Targeted by Suspected Chinese-Speaking Operator Using Known Vulnerabilities,” August 26, 2026; OpenAI, “OpenAI–Hugging Face Incident Technical Report,” August 26, 2026; Red Hat CVE-2026-53362 advisory; JFrog Security Advisory for CVE-2026-66384, August 12, 2026.
Exposed ransomware infrastructure shows Cursor assisting hands-on intrusions
Gambit Security reported on August 27 that an operator associated with the Aurora ransomware operation used Cursor Agent, running Claude Sonnet, during hands-on exploitation across ten target organizations between April 8 and May 21. Gambit obtained this visibility from exposed attacker infrastructure. Reuters independently reviewed portions of the data and identified six affected organizations.
The evidence does not show Cursor autonomously selecting and breaching victims from the public internet. Gambit says the operator supplied the agent with credentials or an existing route into each environment and then directed it to install network-access tools, scan internal systems, enumerate Active Directory privileges, attempt NTLM relay, and test certificate-based attack paths.
In some sessions, the operator specified the tool or procedure. In others, the operator stated an objective and selected from actions proposed by the agent. Gambit found that many commands failed on their first attempt; some eventually succeeded after the agent revised its commands or scripts, while others produced only reports of unsuccessful attempts.
The captured communications support attribution to a Russian-speaking operator, but they do not establish the operator’s nationality or government affiliation. Reuters could not independently determine how much the agent contributed to each intrusion or whether every targeted organization suffered data theft or ransomware deployment.
The operational lesson is acceleration rather than a new, invisible form of compromise. AI-assisted intrusions still produce recognizable evidence of credential use, remote access, directory enumeration, relay attempts, lateral movement, privilege escalation, and data staging. Organizations should concentrate on constraining administrative access, detecting abnormal use of valid credentials, segmenting management systems, and monitoring post-entry behavior.
Watch for: Evidence that Aurora has standardized agentic tooling across additional operators or that commercial AI providers can reliably identify and interrupt this kind of live intrusion support.
Sources: Gambit Security, “Aurora Ransomware Targets ESXi, Abuses Cursor Agent for Exploitation,” August 27, 2026; Reuters, “Russian-speaking cybercriminals used SpaceX’s Cursor AI tool to hack seven companies,” August 27, 2026.
Manchester Airports Group confirms customer-data theft as reports cite 8.7 million records
Manchester Airports Group confirmed on August 27 that an unauthorized party obtained customer information connected to Manchester, London Stansted, and East Midlands airports. Financial Times, Sky News, and other outlets reported that approximately 8.7 million customer records were involved, but MAG’s public statement describes only a quantity of data and does not independently publish that total.
The affected information relates to car-park, lounge, and Fast Track bookings and in-airport Wi-Fi registrations. MAG says the accessed data includes email addresses, telephone numbers, vehicle registrations, and postcodes. The company also says neither MAG nor the accessed system holds customer bank or payment details.
MAG reports that passenger safety, aviation security, airport operations, and parking services were unaffected. Upcoming bookings remain valid, although access to the online Manage My Booking service was temporarily suspended as a precaution.
No public source has established the initial-access method, intrusion duration, attacker identity, ransomware involvement, or whether a supplier or shared booking platform was involved. Claims about the size of the breach should therefore remain attributed to press reporting until MAG or a regulator confirms the record count.
The combination of contact, location, vehicle, and travel-service information creates a credible phishing and impersonation risk. Customers should be skeptical of messages concerning parking charges, booking amendments, refunds, Fast Track access, or requests for payment information. MAG should preserve evidence, review administrative and export activity, rotate credentials and secrets reachable from the affected system, and establish whether access extended beyond the disclosed customer-data environment.
Watch for: Confirmation from MAG or the Information Commissioner’s Office of the record count, intrusion vector, dwell time, affected systems, and any third-party involvement.
Sources: Manchester Airports Group, “Data Security Incident – 27.08.26,” August 27, 2026; Financial Times, “Cyber attack on UK’s largest airport group exposes data of 8.7mn customers,” August 28, 2026; Sky News, “Data stolen from 8.7 million customers after three airports targeted in cyber attack,” August 27, 2026.
Jonathan Brown is a cybersecurity researcher and investigative journalist at bordercybergroup.com.
If you would like to support our work — useful, well-researched, ad-free cybersecurity intelligence — subscribe, comment, or buy us a coffee! Thanks.
Member discussion: