Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports
The Hacker News 05.08.2026 15:14
Two security flaws in Paperclip could let attackers execute commands on a network server or a developer's computer. Paperclip is an open-source control plane for teams of artificial intelligence (AI) agents, and both paths rely on importing a malicious agent and starting it.
A third flaw could expose sensitive data and control-plane details through application programming interface (API) routes
Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug
The Hacker News 05.08.2026 14:27
HashiCorp, Veeam, and the Django Software Foundation have patched 11 vulnerabilities across Terraform MCP Server, Veeam Service Provider Console, and Django.
The three most serious:
An unauthenticated flaw in Veeam's console that hands over a managed agent's credentials, rated 9.5
A cross-tenant flaw in HashiCorp's MCP server that lets one user's Terraform token be reused for later users'
New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch
The Hacker News 05.08.2026 11:43
A memory corruption flaw in the Linux kernel's Open vSwitch datapath gives ordinary local users a path to root on a broad set of default-configured distributions, and a public exploit ships with pre-built records for roughly 800 kernel builds.
The vulnerability, tracked as CVE-2026-64531 (CVSS score: 7.8) and codenamed OVSwrap by its discoverer, was disclosed by security researcher Asim
Cyberangriff auf Ungarn: Hacker stürzt Finanzverwaltung ins IT-Chaos
Golem 05.08.2026 11:10
Ein Angreifer hat IT-Systeme der Finanzverwaltung Ungarns infiltriert. Den Zugriff erhielt er wohl über eine seit 2017 bekannte Lücke in Oracle Weblogic. (Ransomware, Finanzsoftware)
Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup
The Hacker News 05.08.2026 11:04
An unauthenticated attacker can read any file the service account can access on Gitea, the self-hosted Git platform, in versions 1.22.1 through 1.27.0. No login, no repository write access. A public repository and crafted Org-mode markup are enough. The flaw is fixed in Gitea 1.27.1.
The file-read flaw is tracked as CVE-2026-59774, rated Critical with a CVSS score of 9.8, and received its
Sicherheitsupdates: TP-Links Netzwerk-Ökosystem Omada ist kompromittierbar
Heise Security 05.08.2026 09:32
Sicherheitsforscher entdecken unter anderem kritische Lücken in TP-Link Omada, die sich auf weitere Netzwerkkomponenten ausweiten.