The Second PaperCut Patch Still Needs Proof
PaperCut released a second emergency patch after its first response was bypassed. Here is how to restrict access, patch every server, investigate the earlier window, and prove the fix is actually running.
Cybersecurity doesn't have to be complicated. I am here to break down concepts, threats, tips, and tools in simple language. For mere mortals and developers alike.
Since I have been asked this a lot: The best way to support this site, is to buy my books.
PaperCut released a second emergency patch after its first response was bypassed. Here is how to restrict access, patch every server, investigate the earlier window, and prove the fix is actually running.
A targeted lab attack got past Claude Code Auto Mode by turning ordinary-looking steps into code execution. The practical lesson is simple: automated approval can reduce bad decisions, but it cannot contain the computer that makes them.
A Gitea flaw is being exploited after turning ordinary repository access into commands on the server. Here is how to patch, investigate, and rebuild trust in the code and credentials that server could reach.
A fixed Marimo flaw let a crafted notebook start a local command when someone opened it for editing. The practical lesson is simple: notebook configuration belongs inside the code-review boundary.
miniOrange fixed two WordPress login flaws, but six paid editions sat outside the public advisory. Here is how to find the real version, patch it, and check what happened before the fix.
A new Grok proof of concept hid instructions inside encrypted text, then used the model’s own runtime to reveal and act on them. The durable fix is to distrust derived content and control what tools can do with it.
A poisoned Rust package disappeared quickly, but code compiled during that window could have exposed developer and CI credentials. Here is how to check the right evidence and rebuild trust.
An actively exploited MLflow flaw turned webhook delivery into a route toward internal services. Here is how to patch it and reduce what an AI engineering server can reach.
Google says its agent system found more than 100 critical vulnerabilities in two days. The useful lesson for engineering teams is the measured pipeline around the model.
Microsoft fixed a one-click Copilot Personal flaw that could reach data in connected services. The lasting lesson is to treat every AI connector as standing access, with a narrow scope, an owner, and an expiry date.
OpenAI paused parts of its frontier-model work while it tightened research boundaries and monitoring. The useful lesson for engineering teams is how to define a real stop condition before an AI system crosses into the wrong network.
VMware fixed a critical vCenter flaw, but researchers found persistent access on hundreds of systems. Here is how to separate patching from recovery.