Loki Intelligence — Security Briefs · Published

Daily Security Brief: Critical RCEs Hit PaperCut, cPanel, WordPress, and Robots

Today’s risk picture is dominated by high-impact remote code execution and privilege escalation flaws, several already exploited or capable of broad tenant/server compromise. Security teams should prioritize internet-facing patching, hosted-environment isolation, exposure review, and faster vulnerability triage workflows.

Signal 01 · The Hacker News

Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication

Attackers are chaining two recently patched PaperCut NG/MF weaknesses to gain unauthenticated code execution on exposed systems. PaperCut issued an emergency update with added hardening after exploitation activity was observed.

Why it matters: Treat PaperCut as a high-priority patch target, especially where admin interfaces are reachable from untrusted networks; review logs for unusual access and restrict management exposure.

Source: The Hacker News

Signal 02 · BleepingComputer

AI Is Accelerating Vulnerability Discovery. Can Defenders Keep Up?

AI-assisted research is increasing the pace and volume of vulnerability discovery, stressing legacy processes for enrichment, prioritization, and remediation. The article highlights the need to combine intelligence sources rather than rely on single feeds.

Why it matters: Security programs should modernize vulnerability operations with asset context, exploitability signals, and automated prioritization so engineering teams can fix the right issues faster.

Source: BleepingComputer

Signal 03 · The Hacker News

Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server

cPanel patched a critical flaw in domain parking and addon domain handling that could let one hosting customer escalate to root-level code execution on a shared server. The issue affects supported cPanel and WHM versions.

Why it matters: Shared hosting providers should apply updates immediately, verify tenant isolation controls, and watch for suspicious privilege changes or unexpected process activity on multi-user servers.

Source: The Hacker News

Signal 04 · The Hacker News

Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable

A critical balance-handling flaw in the shared Cosmos EVM module was exploited across multiple blockchains, resulting in stolen funds between August 20 and August 25. Cosmos Labs rated the issue critical and warned affected chains using the vulnerable module.

Why it matters: Blockchain operators should rapidly inventory shared dependencies, apply upstream fixes, and add monitoring for abnormal balance movements or contract state changes.

Source: The Hacker News

Signal 05 · BleepingComputer

GiveWP WordPress donation plugin flaw lets hackers execute server commands

A maximum-severity flaw in the GiveWP WordPress donation plugin could allow unauthenticated attackers to run commands on the underlying web server. Sites using the plugin are at elevated risk if they remain unpatched.

Why it matters: WordPress administrators should update the plugin promptly, remove unused plugins, and monitor web servers for unexpected files, processes, or outbound connections.

Source: BleepingComputer

Signal 06 · The Hacker News

ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body

CISA added a critical ownCloud vulnerability to its Known Exploited Vulnerabilities catalog after reports linked exploitation to theft of records from a Philippine nuclear research organization. The activity underscores continued targeting of file-sharing and collaboration platforms.

Why it matters: Organizations running ownCloud should follow KEV remediation timelines, confirm patch status, rotate potentially exposed secrets, and review access to sensitive document repositories.

Source: The Hacker News

Signal 07 · The Hacker News

Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth

Researchers disclosed two root-level remote code execution chains affecting Unitree G1 EDU humanoid robots, including one path involving Bluetooth Low Energy exposure. The vulnerabilities show how robotics platforms can inherit both cyber and physical safety risks.

Why it matters: Teams deploying robots should apply vendor fixes, limit wireless exposure, segment robot networks, and include operational safety checks in vulnerability response plans.

Source: The Hacker News

Brief sources

Related briefs

Relevant Loki services: Orvyn — AI agent security private preview and SKYEN web & API pentesting.