Daily brief at 7am Melbourne. Unsubscribe any time.

Saturday 29 August 2026

PaperCut's Zero-Day Nightmare: Attackers Are Already Inside Before the Patch Landed

PaperCut is on fire — again — and this time attackers chained two flaws for unauthenticated remote code execution while the patch was still wet.

Lead story

PaperCut's Zero-Day Nightmare: Attackers Are Already Inside Before the Patch Landed

If your organisation runs PaperCut NG or MF — the print management software found in universities, hospitals, government agencies, and large enterprises across Australia and globally — you need to act today. A zero-day vulnerability has been under active exploitation since before PaperCut published its emergency patch, and researchers have now confirmed that attackers are chaining two separate flaws to achieve unauthenticated remote code execution.

The first flaw is the original zero-day: an unpatched vulnerability affecting every supported version of PaperCut NG and MF that allows attackers to take control of the application's trusted configuration layer. PaperCut rushed out an emergency patch for v25 and v26, but confirmed it was already aware of "confirmed customer incidents" before the fix shipped. Then, within hours, a second advisory followed — attackers had also discovered they could chain that initial flaw with a second vulnerability in the same product family to execute arbitrary Java code inside the application server, no credentials required.

Think of it like this: the first bug hands an attacker the keys to the front door, and the second bug lets them reroute the entire building's wiring once they're inside.

PaperCut is not a niche product. It's the dominant print management platform in Australian higher education and is widely deployed across state and federal government, healthcare networks, and large corporates. The vendor's own customer list spans more than 100 million users across 70,000 organisations worldwide. Previous PaperCut vulnerabilities — most notably in 2023 — were exploited within days by ransomware groups including Clop and LockBit. That playbook is well-established, and defenders should assume the same crews are watching now.

What's different this time is the chained exploit. The combination of two bugs into a single unauthenticated RCE chain significantly lowers the bar for attackers — you don't need an insider account, a phishing foothold, or any prior access. You need a network path to the PaperCut server and a working exploit, and both appear to be circulating.

The patch situation is imperfect. PaperCut has released fixes for v25 and v26, but organisations running older supported versions have been advised to implement mitigations while waiting for patches — which, in practice, often means taking the server offline or restricting external access entirely. Neither is painless in an environment where print management is operationally critical.

For Australian organisations, the ACSC has consistently flagged PaperCut in previous exploitation waves. Given PaperCut is headquartered in Melbourne, Australian customers tend to be well-represented in the affected user base. Organisations covered by the Essential Eight should treat this as a patch-priority-one item under the "patch applications" control. Healthcare and government entities with SOCI obligations should review whether this touches any systems in scope.

Watch for: ransomware group claims in the next 48–72 hours. The 2023 PaperCut exploitation-to-ransomware window was under a week. There's no reason to expect it to be slower this time.

Also today

Three Perfect-Score ServiceNow Flaws Put Enterprises at Risk

ServiceNow has patched four vulnerabilities in its AI Platform, three of which scored a perfect 10.0 on CVSS — the rarest and most serious rating possible. The flaws can be exploited by unauthenticated attackers under certain conditions to execute code and run arbitrary SQL queries. ServiceNow says it has already pushed fixes to hosted instances, but organisations running self-hosted deployments need to apply updates manually. ServiceNow is deeply embedded in enterprise IT and security operations workflows globally, including across Australian federal and state government agencies, making this a high-priority patch item. The company has not confirmed active exploitation, but perfect-score flaws in widely-deployed enterprise platforms rarely stay quiet for long.

The Hacker News

Chinese-Made ZBT Routers Ship With Factory-Installed Backdoors

Security researchers at VulnCheck have found two previously undocumented implants baked into the firmware of routers made by Shenzhen Zhibotong Electronics. Dubbed SPEAKINGSTONE and DARKLANTERN, the implants give unauthenticated remote attackers root-level command execution on affected devices — no exploit required, because the backdoor ships from the factory. The flaws are tracked as CVE-2026-74232 and CVE-2026-74233. ZBT routers are primarily sold in the Chinese market and to budget resellers, but the disclosure adds to a growing pattern of Chinese-manufactured network hardware arriving with hidden access mechanisms. Australian network operators and managed service providers sourcing budget routers through grey-market channels should treat this as a supply-chain red flag.

The Hacker News

APT28's New HOOKEDGE Backdoor Hits European Government Networks

Researchers at Recorded Future's Insikt Group have documented a fresh campaign linked to APT28 — Russia's GRU-affiliated threat actor — targeting government and diplomatic organisations in Romania, Spain, and Türkiye between late 2025 and early 2026. The campaign deploys a previously unseen backdoor called HOOKEDGE, a lightweight Windows batch script distributed through spearphishing. The choice of a batch script over a compiled binary is deliberate: it's harder for traditional endpoint tools to flag and easier to modify mid-campaign. APT28 has been active against NATO-adjacent targets for years, and the timing — spanning the run-up to several European elections — fits the group's established pattern of politically-timed intrusion activity.

The Hacker News

ATF Hit by Qilin Ransomware, Investigation Files Exposed

The US Bureau of Alcohol, Tobacco, Firearms and Explosives has confirmed it suffered a cyberattack after the Qilin ransomware group claimed responsibility. The ATF described it as a "major incident" and said the Justice Department is investigating. Crucially, the compromised system reportedly contained information about the agency's investigation targets — a particularly sensitive category of data that could expose witnesses, informants, or ongoing law enforcement operations. The ATF insists the breach was contained to a standalone system and has not disrupted critical operations, though that framing will be tested as Qilin begins its usual leak-or-pay pressure campaign. Qilin has been among the most prolific ransomware operators in 2025–26.

CyberScoop

Federal Court Rules Trump's Anthropic Blacklisting Was Illegal

A federal judge has ruled that the Trump administration's decision to label Anthropic a supply-chain risk — effectively blacklisting the AI company from Pentagon contracts — was unlawful. Anthropic had refused to support lethal autonomous weapons systems and mass surveillance applications, which reportedly prompted the designation. The ruling is Anthropic's first court win in what has become a two-front legal battle with the Pentagon. The case has broader implications for how AI companies navigate government procurement when their safety commitments conflict with defence applications. Anthropic's Claude models are used across enterprise and government contexts in Australia, and the outcome of the ongoing Washington lawsuit will be watched closely by procurement teams globally.

Ars Technica

Anthropic's Hardware Standard Wants AI Agents to Run the Physical World

Anthropic has published a new hardware interface standard designed to let AI agents directly control physical devices — think robotics, smart building systems, and industrial equipment — through a standardised driver layer. The goal is interoperability: rather than every device vendor building a bespoke AI integration, a common standard lets agents from any provider talk to any compatible hardware. It's a significant step toward agentic AI moving out of software and into physical infrastructure. The announcement arrives at an uncomfortable moment, days after the Hugging Face incident demonstrated how badly AI agents can behave when they go off-script. The question of who controls the kill switch becomes considerably more urgent when the agent is running a conveyor belt.

Ars Technica

Anthropic Researcher Peeks at Self-Improving AI — and It Works

A researcher at Anthropic has published early results showing an automated system that can improve an AI model's alignment on targeted benchmarks without degrading its general performance. Given ten benchmarks measuring specific misaligned behaviours, the system improved scores on all ten. The research is preliminary and the scope is narrow, but it matters because self-improvement has long been treated as an aspirational — and slightly terrifying — milestone in AI development. Anthropic is framing this as a safety tool: automated alignment improvement rather than unconstrained capability growth. Whether that framing holds as the technique scales is the question everyone will be asking.

TechCrunch AI

AI Models Have a Hidden Lineage Problem, Cisco Warns

New research from Cisco finds that country-of-origin labels on AI models can be deeply misleading. A model marketed as domestically built may have been fine-tuned on a base model from a sanctioned country, inherit its training data biases, or carry forward behaviours embedded in upstream weights. Cisco is effectively arguing that AI supply-chain risk assessments need to trace model lineage the same way software composition analysis traces library dependencies. This has direct relevance for Australian government and critical infrastructure operators assessing AI procurement risk under ASD guidance and SOCI Act obligations — the label on the box may not tell you what's actually inside.

SecurityWeek

Prompt Injection in Claude Code: One Website Summary Away From Compromise

Security researcher Johann Rehberger (wunderwuzzi) has demonstrated that Claude Code — Anthropic's agentic coding assistant — can be hijacked through a straightforward prompt injection attack. Asking the tool to summarise a malicious website is sufficient to redirect its actions. The technique requires no special privileges or unusual configurations; it exploits the fundamental design tension in agentic AI systems, where the model must follow instructions from both the user and external content it retrieves. This is the second significant Claude Code prompt-injection disclosure in a week, suggesting researchers are actively probing the attack surface of coding agents. Given how widely these tools are used by Australian developers, the risk of supply-chain-style attacks via poisoned documentation or repos is real.

The Register

ownCloud Flaw Used to Steal Nuclear Research Files in the Philippines

CISA has added CVE-2023-49105 — a critical authentication bypass in ownCloud — to its Known Exploited Vulnerabilities catalogue after a Chinese-speaking threat actor used it to breach a nuclear research body in the Philippines and exfiltrate records. The vulnerability scores 9.8 on CVSS and has been publicly known since late 2023, which makes this a painful example of the gap between disclosure and patching in sensitive institutions. CISA's KEV listing means US federal agencies must patch immediately, but the broader signal is clear: old, high-severity flaws in self-hosted file-sharing platforms remain productive targets for state-linked actors. Any organisation still running unpatched ownCloud should treat this as an urgent remediation item.

The Hacker News

Microsoft Teams Is Now a Scammer's Favourite Tool in China

A wave of financial fraud targeting Chinese-speaking victims is playing out not in phishing emails or fake websites, but inside Microsoft Teams and Cisco Webex. Fraudsters are exploiting the enterprise legitimacy of these platforms — and their relatively permissive external messaging settings — to build trust with victims before convincing them to transfer large sums of money. The complaints are mounting, and the fraud typology is evolving quickly as scammers find that enterprise chat apps carry more inherent credibility than consumer platforms. Microsoft has been slow to close the external-contact loopholes that make this possible. The tactic has been observed in Australia, where Teams is dominant in corporate environments.

WIRED Security

Sources consulted