Archive for August 2026
PaperCut RCE Vulnerability Actively Exploited
A newly disclosed PaperCut RCE vulnerability is already being exploited against PaperCut NG and PaperCut MF print management servers worldwide. PaperCut confirmed active attacks on August 27, 2026, shipped an emergency patch within hours, then replaced it with a hardened second patch the next morning after researchers found the first fix incomplete. Every organization running…
Read MoreBerlin Ransomware Attack: State Refuses to Pay
A Berlin ransomware attack has put Germany’s capital in the position every public-sector CISO dreads: a confirmed data breach, a seven-figure ransom demand, and an election three weeks away. The ransomware group Rhysida claims it stole 5.79 terabytes from Berlin’s state administrative network and is demanding 30 Bitcoin, roughly €2.05 million, with a seven-day auction…
Read MoreTop 5 Cybersecurity News Stories August 28, 2026
This week’s Cybersecurity News Stories August 28, 2026 arrives with a pattern that cuts across every story: the infrastructure that organisations designate as trusted — the identity service that decides who gets access, the security tool that watches for threats, the developer pipeline that builds and deploys code, the video conferencing platform that carries internal…
Read MoreminiOrange SAML SSO Bypass Vulnerability
A miniOrange SAML SSO bypass is under active exploitation against WordPress sites, and most vulnerability scanners cannot detect whether a given site is actually affected. Two chained authentication bugs, CVE-2026-61979 and CVE-2026-15981 (CVSS 9.8 each), let an unauthenticated attacker forge a SAML login and access wp-admin as any existing user, including administrators. DigitalOcean confirmed exploitation…
Read MoreGitLab GraphQL code injection vulnerability
A GitLab GraphQL code injection vulnerability is now under active exploitation, reproduced and attacked within minutes of GitLab’s August 17, 2026 disclosure of CVE-2026-19478. The unauthenticated flaw (CVSS 9.4) lets an attacker delete public projects, forge fake fix records, or lock out maintainers on any unpatched self-managed GitLab instance. GitLab.com and GitLab Dedicated were already…
Read More
