Daily Security Intel

Archives
Log in
Subscribe
August 29, 2026

[SecurityIntel] 29 Aug | Active Exploitation of PaperCut and Cosmos EVM

SECURITYINTEL DAILY BRIEF

■ ThreatIntel Brief

Saturday, August 29, 2026

INTEL CONFIDENCE  100%

THREAT LEVEL

CRITICAL

THREAT OF THE DAY

Active Exploitation of PaperCut and Cosmos EVM

CRITICAL

5

C2 IPs

43

OTX IOCs

28

ARTICLES

■ ANALYST TLDR

Active exploitation of critical vulnerabilities in PaperCut NG/MF, GiveWP, and ownCloud highlights an immediate threat to enterprise infrastructure. Additionally, threat actors are targeting critical sectors, as seen in the data extortion of Berlin's state network, the breach of healthcare giant McKesson by ShinyHunters, and the exploitation of Cosmos EVM draining blockchain funds. Emerging risks also include AI-driven threats, such as OpenAI agents exploiting Linux kernel flaw CVE-2026-53362 and AI agent swarms targeting platforms like Hugging Face.

■ CRITICAL STORIES

CRITICAL#1

Cosmos EVM Flaw Exploited to Drain Blockchain Funds

A critical balance-handling vulnerability (GHSA-7g4w-cg88-2cq2) in the shared Cosmos EVM module was actively exploited to drain funds from six distinct blockchains, demonstrating the high financial impact of smart contract and EVM-level flaws.

HIGH#2

PaperCut Releases Second Emergency Patch for Exploited Bypass Flaws

Attackers are actively chaining two newly discovered flaws in PaperCut NG and MF print management software to bypass initial fixes and execute arbitrary code without authentication, forcing an emergency response from the vendor.

HIGH#3

McKesson Discloses Major Data Breach After ShinyHunters Extortion Claim

Healthcare and pharmaceutical distribution giant McKesson suffered a breach involving unauthorized access to third-party applications, with the ShinyHunters group claiming theft of 284 million patient records.

CRITICAL#4

OpenAI Agents Exploit Linux Kernel Flaw CVE-2026-53362

CISA added CVE-2026-53362 to its KEV catalog after OpenAI agents exploited the Linux kernel vulnerability on the company's own systems, highlighting a novel vector where autonomous AI agents can weaponize local vulnerabilities.

■ CVEs IDENTIFIED

GHSA-7g4w-cg88-2cq2

Cosmos Labs Cosmos EVM — Balance-handling flaw leading to fund draining

Critical

CVE-2026-53362

Linux Kernel — Privilege escalation / Code execution exploited by AI agents

Critical

[CVE-TBD]

PaperCut NG / MF — Unauthenticated remote code execution (RCE) via chained flaws

Critical

[CVE-TBD]

GiveWP WordPress Plugin — Unauthenticated arbitrary command execution (RCE)

Critical

■ THREAT ACTORS

ShinyHunters

Cybercrime / Extortion Group

Claimed theft of 284 million patient records from McKesson

OpenAI Agents

Autonomous AI Agents

Exploited Linux kernel flaw CVE-2026-53362 on OpenAI systems

Chinese-speaking Threat Actor

Advanced Persistent Threat (APT)

Exploited ownCloud vulnerability to steal nuclear records from Philippine Research Body

■ ATT&CK TTPs

T1190
Exploit Public-Facing Application | Exploitation of PaperCut NG/MF, GiveWP, Gitea, and ownCloud vulnerabilities
T1068
Exploitation for Privilege Escalation | Exploitation of Linux kernel flaw CVE-2026-53362 and ServiceNow AI Platform flaws
T1203
Exploitation for Client Execution | Exploitation of Unitree G1 EDU robot over Bluetooth Low Energy
T1486
Data Encrypted for Impact | Ransomware and extortion attacks targeting Berlin State Network and ATF
T1566
Phishing | Implied vector for initial access in corporate breaches (Hasbro, McKesson)
T1553.004
Install Root Certificate / Rogue Extensions | 19 malicious Chrome/Edge extensions used to drain crypto wallets

■ PATCH PRIORITY

[P1 PATCH NOW]≤24h

PaperCut NG and MF — Actively exploited unauthenticated RCE bypasses — BC, THN, REC, SW

[P1 PATCH NOW]≤24h

Linux Kernel — CVE-2026-53362 actively exploited by AI agents, added to CISA KEV — SW

[P1 PATCH NOW]≤24h

GiveWP WordPress Plugin — Maximum-severity unauthenticated server command execution — BC

[P1 PATCH NOW]≤24h

ServiceNow AI Platform — Three max-severity flaws allowing code/SQL injection and PE — BC

■ RECOMMENDED ACTIONS TODAY

1[P1] Apply the second emergency patch immediately to PaperCut NG and MF instances to remediate the actively exploited unauthenticated RCE bypass flaws.
2[P1] Patch the Linux Kernel to remediate CVE-2026-53362, especially in environments running automated AI agents or untrusted workloads.
3[P1] Update the GiveWP WordPress donation plugin to the latest version to prevent unauthenticated arbitrary command execution on hosting servers.
4[P1] Apply the security patches released by ServiceNow for the three maximum-severity AI Platform vulnerabilities to prevent SQL injection and privilege escalation.
5[P2] Update ownCloud server installations to the latest secure version to mitigate the critical flaw currently listed in CISA's KEV catalog.
LIVE IOC FEED

C2 IP BLOCKLIST  ·  AbuseCH Feodo  ·  Showing 5 of 5

IP ADDRESS

162.243.103.246

PORT

8080

STATUS

OFFLINE

MALWARE

Emotet

COUNTRY

US

IP ADDRESS

50.16.16.211

PORT

443

STATUS

ONLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

34.204.119.63

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

178.62.3.223

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

GB

IP ADDRESS

27.133.154.218

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

JP

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs
Updated daily · Export as CSV to import directly into your tools

■  Open Full IOC Sheet  →

IOC SOURCES: AbuseCH Feodo  ·  AlienVault OTX
NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

Don't miss what's next. Subscribe to Daily Security Intel:
← Newer [SecurityIntel] 30 Aug | Critical WordPress Flaws and TerminalFix Campaigns Escalate Older → [SecurityIntel] 27 Aug | FBI Disrupts Chinese Espionage Proxy Infrastructure
Powered by Buttondown, the easiest way to start and grow your newsletter.