● On the wire
QueryHouse: Cross-DBMS Differential Testing with LLM and Query Transpilation (to appear)//Ubuntu 26.04 LTS GNU cpio Important Input Sanitization Flaws USN-8704-1//Debian Roundcube Important Info Disclosure XSS Denial of Service DSA-6479-1//Ubuntu 24.04 LTS 8643-5 Important Security Update for Linux Kernel//Some Malicious PE Stats, (Thu, Aug 27th)//Prism: A Multi-Team Orchestration of LLM Agents for Automatic Program Repair (to appear)//Ubuntu 24.04 openCryptoki Important Access Issues USN-8686-1//Debian Trixie Linux Kernel Security Fix DSA-6477-1 for Privilege Escalation//Ubuntu 26.04 bzip2 Denial of Service Memory Management Issue USN-8685-1//Debian suricata-update Important Path Traversal Attack CVE-2026-63347//Ubuntu 20.04 Linux Kernel Azure CVM Security Update USN-8658-4//Ubuntu 26.04 diffutils Denial of Service Flaw USN-8692-1//Ubuntu 26.04 OpenJDK 25 Critical Auth Issues USN-8695-1//When it Snows it Pours – Anatomy of a ServiceNow Red Team//Simulating legitimate Active Directory services on the network: the case of GPO exploitation//QueryHouse: Cross-DBMS Differential Testing with LLM and Query Transpilation (to appear)//Ubuntu 26.04 LTS GNU cpio Important Input Sanitization Flaws USN-8704-1//Debian Roundcube Important Info Disclosure XSS Denial of Service DSA-6479-1//Ubuntu 24.04 LTS 8643-5 Important Security Update for Linux Kernel//Some Malicious PE Stats, (Thu, Aug 27th)//Prism: A Multi-Team Orchestration of LLM Agents for Automatic Program Repair (to appear)//Ubuntu 24.04 openCryptoki Important Access Issues USN-8686-1//Debian Trixie Linux Kernel Security Fix DSA-6477-1 for Privilege Escalation//Ubuntu 26.04 bzip2 Denial of Service Memory Management Issue USN-8685-1//Debian suricata-update Important Path Traversal Attack CVE-2026-63347//Ubuntu 20.04 Linux Kernel Azure CVM Security Update USN-8658-4//Ubuntu 26.04 diffutils Denial of Service Flaw USN-8692-1//Ubuntu 26.04 OpenJDK 25 Critical Auth Issues USN-8695-1//When it Snows it Pours – Anatomy of a ServiceNow Red Team//Simulating legitimate Active Directory services on the network: the case of GPO exploitation//
PaperCut: la patch di emergenza 2 chiude la catena RCE sfruttata
Top story — News

PaperCut: emergency patch 2 closes the exploited RCE chain

PaperCut has released Emergency Patch Release 2 after researchers demonstrated that the first fix could be bypassed against a pre-authentication remote code execution chain that was already being actively exploited. The flaw affects PaperCut NG and MF, products used in schools, hospitals, and offices, so the potential target base is enormous. Huntress observed real-world activity and reconstructed the entire chain…

Read the article →
From the newsroom
Spotlight
More news