AUTO-UPDATED

Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities

Cybersecurity researchers at Arctic Wolf report that threat actors are actively exploiting critical PaperCut vulnerabilities to steal credentials and compromise educational institutions across the United States and Europe.

Key Points

  • Attackers are chaining CVE-2026-81578 and CVE-2026-82078 to bypass authentication and execute remote code on vulnerable PaperCut servers.
  • Malicious activity includes creating privileged accounts, deploying credential-harvesting tools like lsa_collect.exe, and extracting sensitive system registry data.
  • Researchers identified malicious traffic originating from IP addresses 45.142.193.132 and 194.180.48.134 to facilitate data exfiltration and establish Meterpreter sessions.
  • Compromised systems are being searched for configuration files containing passwords, LDAP credentials, and security tokens.
  • Security teams are advised to restrict internet exposure for PaperCut servers and monitor for suspicious command-line activity originating from the pc-app.exe process.

Why it Matters

These exploits pose a significant risk to educational organizations by providing attackers with a gateway to broader network infiltration through stolen administrative credentials. Securing these servers is essential to prevent unauthorized access to sensitive institutional data and the potential escalation of attacks into critical infrastructure.
Internet Published by info@thehackernews.com (The Hacker News)
Read original