Latest cyber news, threats, security, and guidelines. Stack up.

Latest

Last 3 days · one card, one id
Incident
Published 2026-08-27
Verified 2026-08-29

AFP, WAPF and FBI charge two WA men over alleged open-source supply-chain syndicate

Joint AFP, Western Australia Police Force and FBI release: two West Australian men were charged on 26 August 2026 with a combined 14 offences after Perth search warrants. Police allege a syndicate inserted malicious code into software on an open-source repository that other developers then pulled in. The AFP estimates more than 1,000 organisations globally, more than 500,000 credentials, and at least 300 GB of data, with remediation costs in the hundreds of millions of dollars. The FBI statement in that release names the group TeamPCP. The men are not named in the AFP release. The investigation continues; further arrests have not been ruled out.

Exploited in Australia?
unknown

Primary: AFP media release · ABC News (secondary)

australia supply chain

Vulnerability
Published 2026-08-27
Verified 2026-08-29

PaperCut NG/MF: active exploitation; Emergency Patch Release 2 (CVE-2026-82078, CVE-2026-81578)

PaperCut Software's 27 August 2026 (AEST) security bulletin, last updated 28 August, says its response team is investigating active exploitation of PaperCut NG and PaperCut MF, with confirmed customer incidents. The advisory applies to all versions of both products. Immediate action: if the Application Server is reachable from the public internet, restrict web access to trusted addresses now. At 8:42pm AEST on 28 August, PaperCut published Emergency Patch Release 2 for NG/MF v25 and v26 (Windows, Linux and macOS), with extra hardening after work with Huntress and watchTowr. At 10:08pm AEST the same day it published Release 2 for v24 as well. Install Release 2 even if you already applied the original emergency patch. Versions before v24 should upgrade to the latest. The bulletin now lists CVE-2026-82078 (unsafe dynamic class loading in the database connector, CVSS 4.0 9.4 Critical) and CVE-2026-81578 (authentication bypass that can let an unauthenticated remote attacker modify certain system configurations, CVSS 4.0 8.8 High). Site Servers and secondary/print servers should be updated, not only the primary Application Server. Print Deploy and Mobility Print are not affected. ASD's ACSC had not published a matching PaperCut alert at last check.

Product
PaperCut NG and PaperCut MF
Versions
All versions of NG and MF
CVSS
(CVE-2026-82078, CVSS 4.0, PaperCut); 8.8 (CVE-2026-81578, CVSS 4.0)
Exploited in Australia?
unknown
Patch to
Emergency Patch Release 2 for v24, v25 and v26; restrict public web access now; upgrade pre-v24 to latest

Primary: PaperCut security bulletin (27 Aug 2026) · Vendor: PaperCut (vendor) · CVE: CVE-2026-82078, CVE-2026-81578 · CVE-2026-82078

vulnerabilities australia