Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (29 August 2026)
Published: Loading…
At a Glance
- PaperCut NG and MF are under active zero-day exploitation via CVE-2026-81578 and CVE-2026-82078, enabling unauthenticated remote code execution.
- Ten malicious versions of @7nohe/openapi-react-query-codegen were published via a misconfigured GitHub Actions workflow, deploying a self-propagating credential-harvesting worm.
- ServiceNow patched three critical AI platform flaws, including two code injection bugs and one SQL injection, all exploitable without authentication.
- 824 IP addresses across 795 networks impersonated AI crawlers from Anthropic, OpenAI, Google, and Perplexity to harvest exposed credential files.
- ZBT routers ship with two factory-implanted backdoors, SPEAKINGSTONE and DARKLANTERN, granting unauthenticated root access remotely.
- Australian Federal Police arrested two alleged TeamPCP members in Perth following a joint investigation with the FBI into supply chain attacks.
Editorial Analysis
Three critical or maximum-severity unauthenticated remote code execution vulnerabilities were disclosed today, affecting PaperCut NG and MF, the GiveWP WordPress plugin, and three components of the ServiceNow AI platform. Their concentration coincides with a CISA finding published in the same 24-hour window: injection flaws, missing authentication for critical functions, and improper input validation remain among the most exploited weakness types across the CVE and KEV catalogues. GiveWP and PaperCut both reflect that pattern, combining authentication weaknesses with unsanitised input reaching dangerous functions.
The PaperCut incident also follows a pattern seen with N-able earlier this month. An initial emergency patch was released, bypassed, and replaced with a second fix within hours. The bypass exploited another instance of the same authentication weakness by substituting the Home page for the Error page in the Tapestry direct-request path. The first patch therefore closed the known path without fully addressing the underlying flaw, leaving organisations that had already applied it exposed.
The @7nohe/openapi-react-query-codegen compromise took a different route. The attacker did not need stolen credentials or a vulnerability in GitHub itself: the package's release workflow accepted a trigger comment from any pull-request participant, checked out that participant's code, and published it using a GitHub Actions OIDC token. The workflow's legitimate npm provenance therefore confirmed that the packages had been built by the official publishing process, without confirming that the person who triggered that process was authorised to do so.
Highlights of the Day
PaperCut Zero-Day Chain Lets Attackers Bypass Login, Run Code
PaperCut disclosed CVE-2026-81578 and CVE-2026-82078, an authentication bypass paired with unsafe dynamic class loading in PaperCut NG and MF. Attackers exploit Apache Tapestry request handling to reach privileged components, then reconfigure database settings to trigger remote code execution via a Derby-to-H2 JDBC chain. PaperCut released emergency patches for versions 24 through 26, later issuing a second patch after the first was found bypassable.
GiveWP Flaw Lets Anyone Register, Then Run Server Commands
Patchstack disclosed CVE-2026-82222, an unauthenticated PHP object injection in the GiveWP WordPress plugin affecting versions 4.16.7.1 and below. Attackers self-register an account, plant a serialised gadget via a donation form, then trigger a chain through bundled TCPDF and Give\TestData classes to execute arbitrary commands. GiveWP fixed the flaw in version 4.16.7.2, restricting unserialisation at multiple points and adding a migration to clean previously poisoned data.
Supply Chain Worm Hits npm Package With 150,000 Weekly Downloads
Ten versions of @7nohe/openapi-react-query-codegen were published to npm in 20 minutes after an attacker compromised the project's GitHub Actions workflow, embedding a multi-layered credential-harvesting payload. The malware executes via a binding.gyp Python sandbox escape during package installation, then harvests credentials from AWS, Azure, GCP, GitHub, npm, and local files before exfiltrating them to attacker-controlled public GitHub repositories. The worm propagates by injecting itself into other packages owned by any stolen npm, PyPI, or RubyGems tokens, and backdoors accessible GitHub repositories with malicious workflow and IDE configuration files.
Insecure GitHub Actions Workflow Enabled npm Package Takeover
An attacker exploited a release workflow in the @7nohe/openapi-react-query-codegen repository that accepted an npm publish comment from any pull request participant without verifying the commenter's repository role. The workflow then checked out the attacker's pull request code and published it via npm Trusted Publishing using a GitHub Actions OIDC identity, requiring no maintainer password or long-lived token. GitHub user p00paboot triggered the attack via pull requests #215 and #216, resulting in ten malicious versions published within 20 minutes.
ServiceNow Patches Four Flaws Including Three Critical AI Platform Bugs
ServiceNow disclosed four vulnerabilities on 27 August 2026, three rated critical, affecting the Now Platform and ServiceNow AI platform. CVE-2026-18885 and CVE-2026-18886 are code injection flaws enabling unauthenticated remote code execution and privilege escalation respectively, while CVE-2026-74820 allows unauthenticated SQL injection against the instance database. A fourth flaw, CVE-2026-6876, is a high-severity sandbox escape in the Now Platform that could also allow unauthenticated code execution.
Threat Actors Forge AI Crawler Identities to Harvest Exposed Credentials
GreyNoise observed 824 IP addresses across 795 separate networks impersonating AI crawlers from Anthropic, OpenAI, Google, and Perplexity to request exposed credential files such as .env, .aws/credentials, and private keys. None of the addresses matched any of the four companies' published crawler IP ranges, and unlike genuine crawlers, the impostors never once requested robots.txt. Cross-checking connecting addresses against vendors' published IP lists is the only reliable method to distinguish forged from legitimate crawler traffic, as the user-agent string alone is insufficient.
Daily Coverage