// PaperCut
Critical Patch Monday: PaperCut, GiveWP, ownCloud, and Browser Threats Demand Immediate Action
By NeoShield AI Threat Desk · Published 2026-08-31 · 5 min read
#PaperCut#GiveWP#ownCloud#CVE-2023-49105#CISA KEV#infostealer#Chrome extensions#RCE
A wave of actively exploited critical vulnerabilities across print management, WordPress, and file-sharing platforms converges with rising browser-based credential theft — here is what your team needs to prioritize today.
PaperCut NG and MF print management software is once again at the center of an emergency response. PaperCut has issued a second emergency patch after researchers and threat actors discovered bypass techniques that circumvented the initial fix. This is a significant escalation. When attackers invest effort in defeating a patch, it signals high-value targeting and sustained campaign activity. Organizations running PaperCut in any capacity — including managed print environments and university campuses where the software is common — must apply the latest emergency update immediately and not assume the first patch was sufficient. Verify your installed version against the vendor's current advisory and treat any unpatched PaperCut instance as actively compromised until proven otherwise.
For WordPress administrators, the GiveWP donation plugin presents a critical unauthenticated remote code execution vulnerability. Because exploitation requires no authentication, any internet-facing WordPress site running a vulnerable version of GiveWP is exposed to full server compromise without any user interaction or credential theft required. Attackers can execute arbitrary commands, drop web shells, exfiltrate donor data including payment information, and pivot deeper into hosting infrastructure. Update GiveWP to the patched release immediately, audit your plugin inventory for other outdated components, and consider placing WordPress admin interfaces behind IP allowlisting or a web application firewall with virtual patching rules while updates are applied.
ownCloud's CVE-2023-49105, carrying a CVSS score of 9.8, has now been confirmed in a high-profile attack against a Philippine nuclear research body where threat actors used the flaw to steal sensitive records. CISA has added this CVE to its Known Exploited Vulnerabilities catalog alongside CVE-2026-53362 affecting the Linux kernel and CVE-2026-66384 affecting JFrog Artifactory. The ownCloud exploitation targeting nuclear research infrastructure is a stark reminder that critical vulnerabilities in file-sharing and collaboration platforms are attractive to both nation-state actors and opportunistic criminals. Any organization running ownCloud must patch CVE-2023-49105 without delay, review access logs for anomalous authentication events, and audit what data is accessible through the platform. JFrog Artifactory administrators should treat CVE-2026-66384 as equally urgent given its KEV status, as Artifactory sits at the heart of software supply chains and a compromise there can cascade into build pipeline and software distribution attacks.
Shifting to the endpoint and browser layer, Anthropic has warned that infostealer malware is actively harvesting live Claude session tokens from infected machines, allowing attackers to hijack authenticated sessions and drain API usage quotas or access sensitive conversation history. Separately, multiple malicious extensions discovered in the Chrome Web Store and targeting Microsoft Edge users were found to steal cryptocurrency wallet data, browser history, and sensitive form data, while also injecting ClickFix social engineering lures to further compromise victims. These two threats are connected by a common attack surface: the browser. Employees increasingly conduct sensitive work — including interactions with AI tools, cloud consoles, and financial platforms — entirely within the browser, making it a high-value target.
Defensive priorities for your team today:
- Apply PaperCut's second emergency patch immediately and verify version currency against the official vendor advisory; do not rely on the first patch alone.
- Update GiveWP on all WordPress instances and restrict wp-admin access to trusted IP ranges; deploy WAF rules as a compensating control.
- Patch ownCloud against CVE-2023-49105 and review authentication logs for signs of prior exploitation; treat JFrog Artifactory CVE-2026-66384 and Linux kernel CVE-2026-53362 as equally urgent given CISA KEV listing.
- Audit all installed browser extensions across your organization using endpoint management tooling; remove unrecognized or low-reputation extensions and enforce an allowlist policy where feasible.
- Deploy endpoint detection capable of identifying infostealer behavior such as credential database access and browser storage enumeration; enforce short session token lifetimes and require re-authentication for sensitive platforms.
- Educate users that AI platform sessions carry real value to attackers and should be protected with the same discipline as cloud console credentials, including MFA and endpoint hygiene.
- Cross-reference your asset inventory against all three new CISA KEV entries and ensure remediation timelines comply with your organization's KEV policy.
The convergence of server-side RCE vulnerabilities with browser-layer session theft illustrates that attackers are pursuing every available path simultaneously. A patched server means little if an administrator's browser session is stolen minutes later. Defense requires both layers to be addressed in parallel.
This briefing is informational and for situational awareness only — always consult official vendor advisories and CISA guidance as the authoritative source for remediation details.
Related articles
PaperCut Under Fire, Malicious Extensions, and Crypto Chaos: September 1 Threat Briefing
Active exploitation of two critical PaperCut vulnerabilities headlines a turbulent day alongside malicious Chrome extensions…
PaperCutPatch Chains, KEV Additions, and Supply Chain Arrests: August 30 Threat Briefing
A wave of critical exploited vulnerabilities across print management, file sharing, Linux, and artifact repositories demands…
PaperCutPatch Chains, KEV Additions, and Supply Chain Arrests: August 29 Threat Briefing
A wave of actively exploited critical vulnerabilities across print management, file sharing, and developer infrastructure demands…
NeoShield Security publishes defensive cybersecurity guides for developers, small teams, SOC learners, and MSPs. AI-assisted content is reviewed for safety, defensive purpose, and practical security value.