LIVE · cybersecurity feed
Live wire
Broadcom Patches Critical VMware Workstation and Fusion VM-Escape VulnerabilitiesHackers Leak Millions of Airport Passenger Records After Ransom RefusalCVE-2026-14894 · Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE FlawsCisco searched for IOS XR bugs and found so many it rolled them into an update releaseAttackers exploit zero-days in consistently besieged SonicWall productIntroducing context-aware vulnerability discovery and remediation with Cloudflare Managed Defense and OpenAI Daybreak modelsHPE patches critical ArubaOS-CX remote code execution flawCVE-2026-82329 · Attackers Pounce on Critical Artifactory Flaw Following DisclosureCVE-2026-0768 · Critical Langflow flaw exploited to steal OpenAI and AWS keysCVE-2026-82329 · Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure
CVE-2026-81578

Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities

Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as

zeroday.news ·

Recent reports indicate that threat actors are actively exploiting newly disclosed vulnerabilities in PaperCut software to steal credentials, primarily targeting the education sector across the U.S. and Europe. The Arctic Wolf Adversary Research Team has observed these attacks, detailing the use of an authentication bypass and remote code execution chain to achieve command execution and conduct reconnaissance within affected environments.

The vulnerabilities in question are identified as CVE-2026-81578 and CVE-2026-82078. The former, an authentication bypass, allows attackers to circumvent security measures designed to verify user identity. This bypass likely grants unauthorized access to parts of the PaperCut system that should be restricted. Following this, the remote code execution (RCE) flaw, CVE-2026-82078, enables attackers to execute arbitrary code on the compromised server. This combination of flaws provides a potent pathway for adversaries to gain significant control over the affected systems.

PaperCut, a print management software, is widely used in educational institutions and other large organizations to control and monitor printing, copying, and scanning. Its pervasive deployment within these environments means that a compromise could impact a substantial number of user accounts and potentially provide a foothold into broader network infrastructure. The nature of the software, often integrated with directory services, makes credential theft a particularly high-value objective for attackers.

The observed attack chain involves initial exploitation of the authentication bypass, followed by leveraging the RCE vulnerability. Once remote code execution is achieved, attackers can perform various malicious activities, including command execution for system manipulation and reconnaissance to map out the network and identify further targets. The ultimate goal, as reported, is credential theft, suggesting that attackers are likely harvesting usernames and passwords from compromised PaperCut servers or related systems.

Mitigation for this class of vulnerability typically involves applying vendor-provided patches immediately. Organizations using PaperCut software should prioritize updating their installations to the latest secure versions to remediate CVE-2026-81578 and CVE-2026-82078. Beyond patching, implementing strong network segmentation can limit the lateral movement of attackers even if an initial compromise occurs. Monitoring for unusual activity on PaperCut servers, such as unexpected command execution or outbound connections, is also critical for early detection. Furthermore, organizations should enforce multi-factor authentication (MFA) for all services, especially those handling sensitive credentials, to reduce the impact of stolen passwords.

This incident underscores the critical importance of timely patching and robust security practices, particularly for software that manages core services within an organization. The education sector, often a target due to its extensive user base and sometimes less mature security postures compared to other industries, must remain vigilant against such sophisticated attacks. The exploitation of newly disclosed flaws highlights the shrinking window between vulnerability disclosure and active exploitation, emphasizing the need for rapid response and proactive defense strategies.

vulnerabilitycloud
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerabilitycritical

Broadcom Patches Critical VMware Workstation and Fusion VM-Escape Vulnerabilities

Broadcom patched two VMware Workstation/Fusion VM-escape bugs. No workarounds exist. Update to version 26H1u1 immediately. Broadcom published advisory VMSA-2026-0007, patching two vulnerabilities in VMware Workstation and Fusion that allow an attacker inside a virtual machine to execute code on the underlying host. One is rated Critical. Neither has a workaround. The first vulnerability, tracked a

CVE-2026-85046

U.S. CISA adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Google Chromium V8 flaw, tracked as CVE-2026-85046 (CVSS score of 8,8), to its Known Exploited Vulnerabilities (KEV) catalog. This week, Google released a Chrome security update fixing 12 [

ai

[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI

ai

[Virtual Event] Building a Secure AI Strategy for the Enterprise

nation-state

Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordination Channel

A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox. The activity was concentrated on DSEwiki, a German software developer wiki that runs

ai

numbat - AI agent observability, (Fri, Sep 4th)