Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities

Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities
Threat actors are exploiting newly disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, to steal credentials and gain privileged access in attacks against education organizations in the U.S. and Europe. Arctic Wolf reported post-exploitation activity including reconnaissance, registry hive collection, Meterpreter payload delivery, and searches for sensitive configuration data on compromised servers. #PaperCut #CVE-2026-81578 #CVE-2026-82078 #ArcticWolf

Keypoints

  • Attackers are chaining PaperCut flaws to achieve authentication bypass and remote code execution.
  • The campaign is targeting K-12 schools and universities in the U.S. and Europe.
  • Post-exploitation activity includes discovery commands, registry hive collection, and privileged account creation.
  • Malicious infrastructure was used to deliver credential-harvesting tools and Meterpreter Java payloads.
  • Defenders should restrict PaperCut internet exposure and monitor for suspicious command-line activity.

Read More: https://thehackernews.com/2026/09/attackers-exploit-papercut-flaws-to.html