All CosmicBytez Labs articles tagged #PaperCut, across news, security advisories, how-to guides, and projects.
PaperCut shipped maintenance releases for two actively exploited CVEs after a Russian-speaking actor hit 395 orgs in 48 countries using AI agents.
Attackers exploiting PaperCut NG/MF's patched auth-bypass and RCE chain have pivoted to dumping database tables instead of deploying payloads.
Critical unsafe reflection flaw in PaperCut NG/MF lets attackers run arbitrary Java code; now on CISA's KEV list and tied to active data theft.
ShinyHunters' deadline hits as McKesson confirms a breach, a critical Langflow RCE bleeds AI-agent keys, and PaperCut's patched zero-days pivot to data theft.
PaperCut ships Emergency Patch Release 2 for CVE-2026-81578 and CVE-2026-82078 after researchers bypassed the first fix in active attacks.