PaperCut Gets Worse and Cosmos Knew (08/29/2026)

August 29, 2026
PaperCut Gets Worse and Cosmos Knew (08/29/2026)
Key Intel / TL;DR
  • PaperCut has two chained flaws, CVE-2026-81578 at 8.8 for authentication bypass and CVE-2026-82078 at 9.4 for code execution, needing no credentials.
  • Researchers have already found new bypasses affecting the latest fully patched version, so patching is necessary and may not be sufficient.
  • Cosmos Labs knew by August 13 that every chain was at risk, shipped a silent patch anyway, and six blockchains lost about $5.7 million.
  • ServiceNow patched four AI Platform flaws, three of them scoring 10.0.
  • Berlin has refused to pay extortion after the compromise of the city's state administrative network.

Yesterday PaperCut was an undisclosed zero-day. Today it has two CVEs, a documented attack chain, and a second emergency patch that researchers have already found ways around. If you run it and you have not taken the management interface off the internet, that is still the only mitigation you fully control.

Top 5 Critical Security Alerts

1. Two Chained PaperCut Flaws Give Code Execution With No Credentials

CVE-2026-81578, scoring 8.8, is an improper access control flaw in the web management interface that lets unauthenticated remote requests reach administrative functions. CVE-2026-82078, scoring 9.4, is unsafe dynamic class loading in the database connection utilities. Chained, the first bypasses authentication and the second turns an edited configuration file into remote code execution. Observed activity includes Base64-encoded commands, Java class files, machine fingerprinting, and deletion of server.log and derby.log. A second emergency patch covering versions 24, 25, and 26 adds hardening beyond the first, and researchers have identified new bypasses affecting the latest fully patched version. The Hacker News

Operator Note: Patch, and then do not treat patching as the end of it. The log deletion is your detection opportunity, because a missing server.log is cheap to check and hard for an attacker to explain. The Register’s framing is accurate and worth repeating to whoever owns the change window: the realistic options right now are an emergency patch that is still being bypassed, or taking the server off the network. The Register

2. Cosmos Labs Knew Every Chain Was Vulnerable and Patched Quietly Anyway

A balance-handling flaw in the shared Cosmos EVM module, tracked as GHSA-7g4w-cg88-2cq2 with no CVE assigned, allowed a balance to wrap when a vesting account delegated more than its spendable balance. It was reported through the bug bounty on April 25 and initially assessed as no risk to live networks because it could not be reproduced on 18-decimal chains. By August 13 Cosmos Labs had confirmed every chain was affected regardless of decimal configuration. The fix shipped on August 19 through the standard silent patch process, a public pull request describing the exploitation path appeared 8 hours and 15 minutes later, and exploitation began the next day. Six blockchains were drained between August 20 and 25, with roughly $2.87 million sold on decentralized exchanges and $2.85 million on centralized ones. The Hacker News

Operator Note: Their own bug bounty policy says that a network-wide risk triggers private fix distribution and coordinated upgrades before public disclosure. They had the finding, they had the reassessment, and they used the routine channel. The transferable lesson has nothing to do with blockchain: a severity reassessment has to re-trigger your disclosure process, because the process was chosen when the severity was wrong.

3. ServiceNow Patches Four AI Platform Flaws, Three at Maximum Severity

ServiceNow has released patches for four flaws in the AI Platform, three of them rated 10.0 and exploitable in certain circumstances by an unauthenticated attacker, covering code injection, SQL injection, and privilege escalation. BleepingComputer

Operator Note: The AI Platform detail matters more than the scores. These capabilities were switched on across a lot of instances during the last year without a separate security review, because they arrived as a feature of something already deployed and already trusted. Check whether yours is enabled before you decide the advisory is not about you.

4. Berlin Will Not Pay the Extortion Demand

Berlin’s state government has confirmed it is the target of an extortion attempt following the August compromise of the city’s state administrative network, and has said it will not meet the demand. The Hacker News

Operator Note: A public refusal from a government is worth noting because it removes the ambiguity attackers rely on when they price a demand. The harder question, and the one your own tabletop should cover, is what the organization does in the weeks after refusing, since the decision not to pay is the beginning of the incident rather than the end of it.

5. TerminalFix Runs ClickFix Into a Reverse Tunnel

Microsoft Threat Intelligence has published analysis of a ClickFix campaign using fake CAPTCHA prompts, DLL sideloading, and a reverse tunnel. The writeup includes detections and hunting guidance, which is unusual enough to be worth acting on. Microsoft

Operator Note: The reverse tunnel is the part that survives your firewall, since it is an outbound connection the user’s own machine initiates. That makes this the third campaign this week whose entire viability rests on outbound being permitted by default, after the agent escape and the router implants. The hunting guidance is published, which makes this an afternoon of work rather than a project.

Additional Security Alerts

Vulnerabilities & Exploits

  • Five critical WordPress plugin and theme flaws enable site takeover or remote code execution: WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP, three of which we carried separately this week. The Hacker News

The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.

Distribute Intel
Chris Armour
Director of Information Security
Chris Armour
The Breaker & Builder.

Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.

View Profile →
Press & Media

Media Inquiries

For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.

Initialize Terminal

Initiate
Deployment.

Whether you need a full adversarial facility audit or an executive resilience protocol for your leadership team.

Secure the Facility (Assessments)
Secure the Mind (Coaching/Speaking)