<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Patch-Bypass on CuraSec</title><link>https://curasec.metacog.co.kr/tags/patch-bypass/</link><description>Recent content in Patch-Bypass on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Fri, 28 Aug 2026 21:21:40 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/patch-bypass/index.xml" rel="self" type="application/rss+xml"/><item><title>PaperCut second emergency patch after initial fix bypassed in wild</title><link>https://curasec.metacog.co.kr/insights/2026-08-28-papercut-releases-second-emergency-patch-for-exploited-flaws/</link><pubDate>Fri, 28 Aug 2026 21:21:40 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-28-papercut-releases-second-emergency-patch-for-exploited-flaws/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> PaperCut NG and MF are actively exploited and the first fix was bypassed, meaning unpatched and initially-patched instances remain at risk; update to the latest emergency release immediately and verify the new version is applied end-to-end.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> Active exploitation with a bypassed patch means print servers in the estate may already be compromised; build or tune detections for anomalous outbound connections and process spawning from PaperCut service accounts, and sweep logs back to the original disclosure date.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> If PaperCut is in the environment, confirm with engineering that the second emergency patch is deployed and request a status update — active exploitation plus a failed first fix is the kind of event that can escalate to a breach if patching is delayed.&lt;/li>
&lt;/ul></description></item><item><title>ShieldBreak PoC Bypasses Defender Patch, Achieves SYSTEM Privilege</title><link>https://curasec.metacog.co.kr/insights/2026-08-12-shieldbreak-zero-day-poc-claims-microsoft-defender-patch-byp/</link><pubDate>Wed, 12 Aug 2026 11:57:00 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-12-shieldbreak-zero-day-poc-claims-microsoft-defender-patch-byp/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Public PoC on GitHub means the original CVE-2026-50656 patch is insufficient, but EPSS 0.11 and no KEV listing indicate no confirmed active exploitation yet. Monitor Microsoft&amp;rsquo;s advisory for an updated patch and apply it immediately when released; in the interim, audit for any unexpected SYSTEM-level Defender process activity.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> The public PoC provides enough technical detail to build behavioral detections before in-the-wild exploitation begins. Develop signatures for anomalous Microsoft Defender process privilege escalation patterns from the PoC and queue for tuning once exploitation is confirmed.&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> CVE-2026-50656 — CISA KEV: not listed, EPSS 0.11, public PoC on GitHub&lt;/li>
&lt;/ul></description></item></channel></rss>