Threat actors are exploiting newly disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, to steal credentials and gain privileged access in attacks against education organizations in the U.S. and Europe. Arctic Wolf reported post-exploitation activity including reconnaissance, registry hive collection, Meterpreter payload delivery, and searches for sensitive configuration data on compromised servers. #PaperCut #CVE-2026-81578 #CVE-2026-82078 #ArcticWolf
Keypoints
- Attackers are chaining PaperCut flaws to achieve authentication bypass and remote code execution.
- The campaign is targeting K-12 schools and universities in the U.S. and Europe.
- Post-exploitation activity includes discovery commands, registry hive collection, and privileged account creation.
- Malicious infrastructure was used to deliver credential-harvesting tools and Meterpreter Java payloads.
- Defenders should restrict PaperCut internet exposure and monitor for suspicious command-line activity.
Read More: https://thehackernews.com/2026/09/attackers-exploit-papercut-flaws-to.html