Loki Intelligence — Security Briefs · Published
Daily Security Brief: Critical RCEs Hit PaperCut, cPanel, WordPress, and Robots
Today’s risk picture is dominated by high-impact remote code execution and privilege escalation flaws, several already exploited or capable of broad tenant/server compromise. Security teams should prioritize internet-facing patching, hosted-environment isolation, exposure review, and faster vulnerability triage workflows.
Signal 01 · The Hacker News
Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication
Attackers are chaining two recently patched PaperCut NG/MF weaknesses to gain unauthenticated code execution on exposed systems. PaperCut issued an emergency update with added hardening after exploitation activity was observed.
Why it matters: Treat PaperCut as a high-priority patch target, especially where admin interfaces are reachable from untrusted networks; review logs for unusual access and restrict management exposure.
Source: The Hacker News
Signal 02 · BleepingComputer
AI Is Accelerating Vulnerability Discovery. Can Defenders Keep Up?
AI-assisted research is increasing the pace and volume of vulnerability discovery, stressing legacy processes for enrichment, prioritization, and remediation. The article highlights the need to combine intelligence sources rather than rely on single feeds.
Why it matters: Security programs should modernize vulnerability operations with asset context, exploitability signals, and automated prioritization so engineering teams can fix the right issues faster.
Source: BleepingComputer
Signal 03 · The Hacker News
Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server
cPanel patched a critical flaw in domain parking and addon domain handling that could let one hosting customer escalate to root-level code execution on a shared server. The issue affects supported cPanel and WHM versions.
Why it matters: Shared hosting providers should apply updates immediately, verify tenant isolation controls, and watch for suspicious privilege changes or unexpected process activity on multi-user servers.
Source: The Hacker News
Signal 04 · The Hacker News
Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable
A critical balance-handling flaw in the shared Cosmos EVM module was exploited across multiple blockchains, resulting in stolen funds between August 20 and August 25. Cosmos Labs rated the issue critical and warned affected chains using the vulnerable module.
Why it matters: Blockchain operators should rapidly inventory shared dependencies, apply upstream fixes, and add monitoring for abnormal balance movements or contract state changes.
Source: The Hacker News
Signal 05 · BleepingComputer
GiveWP WordPress donation plugin flaw lets hackers execute server commands
A maximum-severity flaw in the GiveWP WordPress donation plugin could allow unauthenticated attackers to run commands on the underlying web server. Sites using the plugin are at elevated risk if they remain unpatched.
Why it matters: WordPress administrators should update the plugin promptly, remove unused plugins, and monitor web servers for unexpected files, processes, or outbound connections.
Source: BleepingComputer
Signal 06 · The Hacker News
ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body
CISA added a critical ownCloud vulnerability to its Known Exploited Vulnerabilities catalog after reports linked exploitation to theft of records from a Philippine nuclear research organization. The activity underscores continued targeting of file-sharing and collaboration platforms.
Why it matters: Organizations running ownCloud should follow KEV remediation timelines, confirm patch status, rotate potentially exposed secrets, and review access to sensitive document repositories.
Source: The Hacker News
Signal 07 · The Hacker News
Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth
Researchers disclosed two root-level remote code execution chains affecting Unitree G1 EDU humanoid robots, including one path involving Bluetooth Low Energy exposure. The vulnerabilities show how robotics platforms can inherit both cyber and physical safety risks.
Why it matters: Teams deploying robots should apply vendor fixes, limit wireless exposure, segment robot networks, and include operational safety checks in vulnerability response plans.
Source: The Hacker News
Brief sources
Related briefs
- How to Evaluate an AI Security Testing Provider
- What Is AI Agent Security Testing?
- AI Red Teaming vs Traditional Pentesting
Relevant Loki services: Orvyn — AI agent security private preview and SKYEN web & API pentesting.