// PaperCut
Patch Chains, KEV Additions, and Supply Chain Arrests: August 30 Threat Briefing
By NeoShield AI Threat Desk · Published 2026-08-30 · 4 min read
#PaperCut#ownCloud#CVE-2023-49105#CISA KEV#Linux Kernel#JFrog Artifactory#WordPress#Cosmos EVM
A wave of critical exploited vulnerabilities across print management, file sharing, Linux, and artifact repositories demands immediate defensive action, while arrests in a major supply chain crime group underscore the persistent human threat behind these campaigns.
The PaperCut situation is a textbook case of patch bypass risk. PaperCut has issued a second emergency update for PaperCut NG and MF after researchers found multiple ways to circumvent the original fixes for two actively exploited vulnerabilities. Organizations that applied the first patch and considered themselves protected are not. If your environment runs PaperCut, treat this as a fresh critical event: update to the latest released version immediately, verify the update applied successfully, and do not assume prior patching is sufficient. PaperCut servers exposed to the internet or accessible from untrusted network segments should be placed behind strict network controls. Review authentication logs for anomalous job submissions, API calls, or administrative account changes dating back at least 30 days, since initial exploitation may predate awareness.
ownCloud's CVE-2023-49105, rated CVSS 9.8, has now been confirmed in attacks targeting nuclear research infrastructure in the Philippines — a stark illustration that critical research institutions are high-value targets for both nation-state and criminal actors. This improper authentication vulnerability allows unauthenticated access to sensitive files and has been added to CISA's Known Exploited Vulnerabilities catalog, meaning federal agencies face a binding remediation deadline and all other organizations should treat KEV listing as a strong signal of widespread exploitation. If you run ownCloud, patch immediately, audit all externally accessible instances, rotate credentials for service accounts connected to ownCloud, and review file access logs for unexpected downloads or authentication events from unfamiliar IP ranges.
CISA's KEV update also adds CVE-2026-53362, a Linux kernel vulnerability, and CVE-2026-66384 affecting JFrog Artifactory. Linux kernel flaws with confirmed exploitation are particularly broad in impact because the kernel underpins servers, containers, and cloud workloads across virtually every enterprise. Prioritize kernel patching on internet-facing and high-value internal Linux hosts, and use your vulnerability management tooling to identify unpatched instances at scale. JFrog Artifactory is a cornerstone of many software supply chains — a compromised Artifactory instance can become a distribution point for malicious packages. Patch Artifactory instances, restrict administrative access to trusted networks, enable audit logging, and review recent artifact uploads and permission changes for signs of tampering.
The arrest of two alleged members of TeamPCP in Australia is significant beyond the headline. TeamPCP is described as responsible for the longest-running software supply chain attack spree on record. While arrests are a positive development, defenders should not stand down. Remaining group members may accelerate activity, and the tactics, techniques, and procedures this group pioneered are now documented and available to other threat actors. Review your software supply chain controls: verify the integrity of third-party packages, enforce code signing, monitor artifact repositories for unexpected changes, and ensure your software bill of materials is current.
WordPress environments face a fresh cluster of critical flaws across five widely used plugins and themes — WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP — enabling authentication bypass, account takeover, and remote code execution. WordPress-based sites remain a high-volume target because the plugin ecosystem creates a large, heterogeneous attack surface. Update all affected plugins and themes immediately, audit user accounts for unauthorized additions or privilege escalations, and consider a web application firewall rule set tuned to WordPress attack patterns as a compensating control while patches are applied.
Finally, the Cosmos EVM vulnerability GHSA-7g4w-cg88-2cq2 resulted in fund drainage across six blockchains over a five-day window after the flaw was publicly known. This is a cautionary tale about disclosure-to-exploitation timelines in shared infrastructure: when a critical flaw exists in a shared module, every dependent platform is simultaneously vulnerable, and attackers move faster than many operators can coordinate patches.
Defensive priorities for today:
- Apply PaperCut's second emergency patch immediately and verify installation; do not rely on prior patching
- Patch ownCloud against CVE-2023-49105 and audit file access logs for unauthorized activity
- Accelerate Linux kernel patching on exposed and high-value hosts for CVE-2026-53362
- Patch JFrog Artifactory for CVE-2026-66384 and audit artifact integrity and access permissions
- Update all five affected WordPress plugins and themes; review admin accounts for unauthorized changes
- Harden software supply chain controls in response to TeamPCP activity and Cosmos EVM lessons
- Cross-reference your asset inventory against the full CISA KEV catalog and close any remaining gaps
This briefing is informational and does not substitute for official vendor advisories and CISA guidance, which should be consulted for authoritative remediation details.
Related articles
PaperCut Under Fire, Malicious Extensions, and Crypto Chaos: September 1 Threat Briefing
Active exploitation of two critical PaperCut vulnerabilities headlines a turbulent day alongside malicious Chrome extensions…
PaperCutCritical Patch Monday: PaperCut, GiveWP, ownCloud, and Browser Threats Demand Immediate Action
A wave of actively exploited critical vulnerabilities across print management, WordPress, and file-sharing platforms converges…
PaperCutPatch Chains, KEV Additions, and Supply Chain Arrests: August 29 Threat Briefing
A wave of actively exploited critical vulnerabilities across print management, file sharing, and developer infrastructure demands…
NeoShield Security publishes defensive cybersecurity guides for developers, small teams, SOC learners, and MSPs. AI-assisted content is reviewed for safety, defensive purpose, and practical security value.