ransomware ⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors This week’s security news is dominated by AI-related threats, including a vulnerability exploited in Metabase, a new Shai-Hulud worm leveraging the MCP Registry, and a Chinese review of Palo Alto Networks. Alongside these, researchers are bypassing Spectre defenses, CSS attacks are targeting webmail, and a new ransomw… The Hacker News · Aug 10, 2026 High CVE-2026-34348CVE-2026-18497CVE-2026-63508CHransomwaresupply-chainvishing
vulnerability Critical Paperclip Flaw Allowed Admin Access, Code Execution A critical vulnerability (CVE-2026-41679) in Paperclip, an AI management platform, allowed remote attackers to gain administrative access and execute code on the server, potentially exposing sensitive data and internal s… SecurityWeek · Aug 6, 2026 Critical CVE-2026-41679aivulnerabilitycode-execution
vulnerability Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports Two critical vulnerabilities in Paperclip, an AI agent control plane, allow attackers to execute commands on a server or a developer's computer. The first vulnerability (CVE-2026-41679) requires no prior account or inter… The Hacker News · Aug 5, 2026 Critical CVE-2026-41679agentauthenticationdns