TL;DR
PaperCut released a second emergency patch after researchers bypassed initial fixes for actively exploited print-management flaws. Cosmos EVM blockchain protocol suffered critical exploitation across six chains, draining funds between August 20–25. Healthcare giant McKesson disclosed a breach affecting 284 million patient records, claimed by the ShinyHunters extortion group.
Executive Summary
- PaperCut NG and MF print-management software are under active exploitation via two chained vulnerabilities; a second emergency patch was released after researchers found ways to bypass the initial fix.
- A critical balance-handling flaw in Cosmos Labs' shared EVM module was exploited to drain funds from six blockchains between August 20 and 25, 2026; the vulnerability (GHSA-7g4w-cg88-2cq2) was published without a CVE.
- McKesson, a major healthcare and pharmaceutical distributor, disclosed unauthorized access to third-party applications and data theft; the ShinyHunters extortion group claims it stole 284 million patient data records.
- ownCloud improper authentication vulnerability (CVE-2023-49105) was weaponized by a Chinese-speaking threat actor to steal nuclear records from a Philippine research body; CISA added it to its Known Exploited Vulnerabilities catalog.
- A maximum-severity flaw in the GiveWP WordPress donation plugin allows unauthenticated attackers to execute arbitrary server commands.
Top Threats Today
1. PaperCut Print-Management RCE Chain – Second Patch Released
Severity: HIGH Affected: Government, Enterprise
Malicious actors are exploiting two chained vulnerabilities in PaperCut NG and MF to execute arbitrary code without authentication on vulnerable instances [1][3]. PaperCut released a second emergency security update after researchers discovered multiple ways to bypass the initial fixes [2]. The company disclosed that the vulnerabilities give an unauthenticated attacker remote control over PaperCut instances, and the first patch did not sufficiently ⚠ harden the attack surface [1].
Sources:[1] The Hacker News[2] BleepingComputer[3] The Record
Recommended Action
- Immediately deploy PaperCut's latest emergency patch to all NG and MF instances
- Review print-server logs for signs of unauthorized access or code execution since August 2026
- Segment print management infrastructure from critical networks until patching is complete
- Monitor for suspicious print job submissions or administrative account creation
2. Cosmos EVM Critical Flaw Exploited Across Six Blockchains
Severity: HIGH Affected: Finance
Cosmos Labs warned that a critical balance-handling flaw in the shared Cosmos EVM module was exploited to drain funds from six blockchains between August 20 and August 25, 2026 [1]. The vulnerability, designated GHSA-7g4w-cg88-2cq2, is rated Critical and was published without a CVE assignment [1].
Sources:[1] The Hacker News
Recommended Action
- Immediately audit wallet and asset balances across all Cosmos EVM–dependent chains for unauthorized transfers
- Coordinate with affected blockchain operators to verify chain integrity and identify all compromised addresses
- Secure any private keys or seed phrases for wallets exposed to vulnerable Cosmos EVM–based chains
- Monitor Cosmos blockchain announcements for emergency upgrades or rollback procedures
3. McKesson Discloses Breach: 284 Million Patient Records Claimed Stolen
Severity: HIGH Affected: Healthcare
Healthcare and pharmaceutical distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft [1]. The ShinyHunters extortion group has claimed it stole 284 million patient data records [1].
Sources:[1] BleepingComputer
Recommended Action
- Coordinate breach notification to all affected patients in compliance with HIPAA and state breach-notification laws
- Monitor credit bureaus and dark web for evidence of patient data sale or use
- Review McKesson's forensics report and third-party application access logs to identify which systems and data types were compromised
- Implement or strengthen access controls and monitoring for third-party integrations in your own healthcare systems
4. ownCloud Authentication Bypass Weaponized Against Nuclear Research Facility
Severity: HIGH Affected: Government, Energy
A critical improper authentication vulnerability in ownCloud (CVE-2023-49105) was weaponized by a Chinese-speaking threat actor to target a nuclear research body in the Philippines [1]. The flaw allows an attacker to access, modify, or delete any file without authentication if the username of a victim is known and the victim has no signing-key configured [2]. CISA added this vulnerability to its Known Exploited Vulnerabilities catalog on August 27, 2026, with federal remediation required by August 30 ⚠[2].
Sources:[1] The Hacker News[2] CISA KEV
Recommended Action
- Immediately patch all ownCloud instances to a version that remediates CVE-2023-49105
- Audit ownCloud access logs for unauthorized file access, modification, or deletion since deployment
- Enforce signing-key configuration for all user accounts
- Isolate ownCloud systems pending patch deployment if critical files are stored
5. GiveWP WordPress Plugin Unauthenticated RCE
Severity: HIGH Affected: Technology, Nonprofit
A maximum-severity vulnerability in the GiveWP plugin for WordPress allows an unauthenticated attacker to execute arbitrary commands on the hosting server [1].
Sources:[1] BleepingComputer
Recommended Action
- Update GiveWP plugin to the latest patched version immediately on all WordPress instances
- If immediate patching is unavailable, disable or remove GiveWP until a patch is released
- Review server logs and WordPress audit trails for signs of unauthorized command execution
- Verify the integrity of donation records and financial transactions post-incident
Today’s Action Checklist
- ☐ URGENT: Deploy PaperCut second emergency patch to all NG/MF instances and verify successful application
- ☐ URGENT: Update or disable GiveWP WordPress plugin across all sites
- ☐ HIGH: Patch or isolate all ownCloud instances vulnerable to CVE-2023-49105
- ☐ HIGH: If you operate or use Cosmos EVM–based chains, audit balances and coordinate with blockchain operators
- ☐ HIGH: If a McKesson customer, request forensics detail and begin patient breach notification process
- ☐ Review print-management infrastructure logs for exploitation attempts in the past 30 days