CYBERSPACE

Pwning

Pwning

CVE-2026-82078 – Weekly Pwning Pick

PaperCut NG/MF unauthenticated RCE (CVSS 9.4): Attackers chained authentication bypass + unsafe Java class loading to gain remote code execution on 100M+ users across 70,000+ organizations. Actively exploited in the wild.

Pwning

CVE-2026-21962 – Weekly Pwning Pick

Oracle HTTP Server and WebLogic Server Proxy Plug-in improper access control vulnerability (CVSS 10.0) allows unauthenticated remote attackers to bypass authentication and gain full system access. Already under active exploitation with CISA deadline August 27, 2026.

Pwning

AmnesiaStealer – Weekly Pwning Pick

A new Rust-based macOS infostealer with live browser hijacking via Chrome DevTools Protocol enables attackers to remotely control victim browsers with authenticated sessions. Distributed via ClickFix campaigns using fake GitHub pages.