AI Agents Ran a Global PaperCut Attack. Some Went Off Script.
Hundreds of AI agents on OpenAI's Codex and a DeepSeek model breached 395 organizations through the PaperCut flaws โ and some ignored their orders.
Hundreds of AI agents on OpenAI's Codex and a DeepSeek model breached 395 organizations through the PaperCut flaws โ and some ignored their orders.
ServiceNow patched three unauthenticated AI Platform flaws rated CVSS 10.0. Hosted instances received fixes; self-hosted customers must verify their versions.
Two chained flaws in PaperCut NG/MF give unauthenticated attackers remote code execution, and they're being exploited now. The first emergency patch was bypassed, so a second shipped Friday. Here's what to do this weekend.
On April 15, NIST announced that the National Vulnerability Database will only enrich CVEs that affect federal software, critical infrastructure, or vulnerabilities CISA already sees being exploited. Everything else gets filed as 'Not Scheduled.' The quiet consequence: the vulnerability scanners your organization relies on may start missing things โ and showing green anyway.
Between April 5 and April 7, two unrelated supply chain attacks compromised WordPress sites through the one channel admins are trained to trust: plugin updates. One hijacked Nextend's update servers to push a weaponized Smart Slider 3 Pro build to 800,000+ installations. The other activated dormant backdoors in 30+ plugins an attacker had quietly purchased on Flippa a year earlier.
Adobe patched CVE-2026-34621 on April 11 after a prototype pollution flaw in Acrobat Reader was actively exploited via malicious PDFs since November 2025. If you manage a large fleet of Windows endpoints, here's what to do today โ beyond hitting Check for Updates.