Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Two security flaws in Paperclip, an open-source AI agent control plane, allow attackers to execute commands on servers or developer computers by importing malicious agents. The most severe vulnerability, CVE-2026-41679, has a CVSS score of 10.0 and requires no authentication.
Two security flaws in Paperclip, an open-source AI agent control plane, allow attackers to execute commands on servers or developer computers by importing malicious agents. The most severe vulnerability, CVE-2026-41679, has a CVSS score of 10.0 and requires no authentication.
This article introduces the RAVEN tool for gathering information about Elasticsearch clusters during penetration testing engagements. It highlights the challenge of encountering an unknown Elasticsearch instance and the need for automated reconnaissance.
This article reports on dark web activities from the first week of August 2026, including the sale of access to a South Korean automotive parts manufacturer's server and database, as well as data from a Turkish HR consulting company. It also notes a Gunra ransomware attack, emphasizing the ongoing threat from ransomware and data breaches.
Google's automated malware detection system incorrectly locked hundreds of legitimate Blogger websites, flagging them as violating malware policies and even deleting some. The false positive, which began on August 4, caused significant disruption for publishers and businesses, highlighting the dangers of automated content moderation without proper recourse.
HashiCorp, Veeam, and Django have patched 11 vulnerabilities, including a critical cross-tenant flaw in Terraform MCP Server (CVSS 10.0) and an unauthenticated credential theft in Veeam Service Provider Console (CVSS 9.5). The flaws are not yet exploited, but operators should update to the latest versions to mitigate risks.