Future TechnologyFuture Technology
← Back to archive
Security Digest

[Cybersecurity Digest] AI just did a 2-week hack in 10 hours

4 September 2026

PaperCut's print server just handed attackers a pre-auth RCE chain, ShinyHunters claims another multi-million record haul, and a ransomware crook used frontier AI to turn a two-week job into a ten-hour one. Patch, check your integrations, and read on.

The Big 3

PaperCut's print server has a pre-auth RCE chain, and attackers found it first

Two chained flaws in PaperCut NG and MF, CVE-2026-81578 and CVE-2026-82078, let an unauthenticated attacker rewrite server configuration and then load arbitrary Java bytecode. PaperCut confirmed active exploitation before either CVE was even assigned, meaning attackers had a head start.

Why it matters: print servers rarely get patched with urgency, but they often carry directory credentials that make them a genuinely useful foothold for lateral movement.

Read more at PaperCut's security bulletin

ShinyHunters claims 5.2 million records from American Tower Corporation

The extortion group says it pulled the data on 3 September from the communications infrastructure giant. It fits a pattern ShinyHunters has run all year: not breaking into networks directly, but harvesting OAuth tokens and API keys from connected SaaS integrations that companies rarely audit.

Why it matters: if your business connects Salesforce, HubSpot or similar platforms to internal systems, a compromised integration token can move data without tripping a single traditional intrusion alert.

Read more at SecurityWeek

A ransomware crook used frontier AI to do a two week job in ten hours

Unit 42 researchers documented a human attacker pairing with AI models to plan and execute a network intrusion that would normally take a skilled team about two weeks. This one finished in under ten hours, with the AI handling reconnaissance and lateral movement planning.

Why it matters: detection processes built around a days-to-weeks attacker timeline are running out of time. Detection speed now matters more than detection coverage alone.

Read more at The Register


Quick Hits

Berlin's city government is being extorted after attackers exfiltrated 5.79 TB of data from municipal systems.

The US ATF confirmed a breach of a stand-alone system after the Qilin ransomware gang claimed responsibility, though no evidence has surfaced yet.

Boston Scientific's global operations were brought to a standstill by a disruptive cyberattack this week.

Eastlink, a Canadian telecom provider, disclosed a breach that may have exposed data on 75,000 customers.


Tool of the Week

YubiKey 5C NFC is a hardware security key that replaces SMS and app-based codes with phishing-resistant authentication. Given this week's stories about stolen OAuth tokens and credential-based breaches, a physical key is one of the few things that stops an attacker who already has your password.

Who it's for: anyone with an account worth protecting properly, especially email, banking and any SaaS admin login.

YubiKey 5C NFC on Amazon UK


Protect Yourself

AI-assisted phishing and social engineering are driving a surge in convincing sign-in prompts and MFA requests you didn't trigger. Treat any unexpected MFA push notification or login approval request as a red flag, not an annoyance. Deny it, then immediately change the password on that account and check its recent sign-in activity. If your accounts support number-matching MFA instead of a simple approve or deny tap, turn it on, it closes the gap that makes accidental approvals so easy.


Forwarded this? Get your own cybersecurity briefing at futuretechnologyhq.com/newsletter

Stay safe out there. Nath, Future Technology

Some links in this newsletter may be affiliate links. We only recommend products we genuinely think are worth your time.