Seite wählen

06.08.2026

Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports

The Hacker News 05.08.2026 15:14
Two security flaws in Paperclip could let attackers execute commands on a network server or a developer's computer. Paperclip is an open-source control plane for teams of artificial intelligence (AI) agents, and both paths rely on importing a malicious agent and starting it.

A third flaw could expose sensitive data and control-plane details through application programming interface (API) routes

Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug

The Hacker News 05.08.2026 14:27
HashiCorp, Veeam, and the Django Software Foundation have patched 11 vulnerabilities across Terraform MCP Server, Veeam Service Provider Console, and Django.

The three most serious:

An unauthenticated flaw in Veeam's console that hands over a managed agent's credentials, rated 9.5
A cross-tenant flaw in HashiCorp's MCP server that lets one user's Terraform token be reused for later users'

New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch

The Hacker News 05.08.2026 11:43
A memory corruption flaw in the Linux kernel's Open vSwitch datapath gives ordinary local users a path to root on a broad set of default-configured distributions, and a public exploit ships with pre-built records for roughly 800 kernel builds.

The vulnerability, tracked as CVE-2026-64531 (CVSS score: 7.8) and codenamed OVSwrap by its discoverer, was disclosed by security researcher Asim

Cyberangriff auf Ungarn: Hacker stürzt Finanzverwaltung ins IT-Chaos

Golem 05.08.2026 11:10
Ein Angreifer hat IT-Systeme der Finanzverwaltung Ungarns infiltriert. Den Zugriff erhielt er wohl über eine seit 2017 bekannte Lücke in Oracle Weblogic. (Ransomware, Finanzsoftware)

Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup

The Hacker News 05.08.2026 11:04
An unauthenticated attacker can read any file the service account can access on Gitea, the self-hosted Git platform, in versions 1.22.1 through 1.27.0. No login, no repository write access. A public repository and crafted Org-mode markup are enough. The flaw is fixed in Gitea 1.27.1.

The file-read flaw is tracked as CVE-2026-59774, rated Critical with a CVSS score of 9.8, and received its

Sicherheitsupdates: TP-Links Netzwerk-Ökosystem Omada ist kompromittierbar

Heise Security 05.08.2026 09:32
Sicherheitsforscher entdecken unter anderem kritische Lücken in TP-Link Omada, die sich auf weitere Netzwerkkomponenten ausweiten.