AI Weekly Malaysia

Back to items Summaries

Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities

ID
21745
Status
summarized
Published
05 Sep 2026, 3:31 PM
Fetched
05 Sep 2026, 4:59 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/attackers-exploit-papercut-flaws-to.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
3.0
Created
05 Sep 2026, 4:59 PM
Tags
Audience
developers

What happened

Arctic Wolf reports attackers exploiting two newly disclosed PaperCut vulnerabilities (CVE-2026-81578, an authentication bypass, and CVE-2026-82078, an RCE) to steal credentials from U.S. and European schools and universities. Post-exploitation includes deploying Meterpreter Java payloads, credential-harvesting tools like lsa_collect.exe, creating privileged accounts (e.g. 'Administrator17'), and searching PaperCut config files for passwords, secrets, LDAP bind credentials, and tokens.

Why it matters

If your organization runs PaperCut print management servers exposed to the internet, restrict that exposure immediately and monitor for cmd.exe/powershell.exe spawned by pc-app.exe with commands like whoami, tasklist, ver, or uname. For most builders not running PaperCut, there is no direct action item.

Discussion angle

A quick reminder segment: print management software is often internet-exposed and forgotten in patch cycles — worth checking whether any infrastructure your team touches has similar neglected admin panels.

Top