Close Menu
AIToday7

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    See the New ‘Mystery Science Theater 3000’ Intro With a Theme by Jonathan Coulton [Exclusive]

    September 7, 2026

    5 4-Door Sedans That Are Surprisingly Good In Snow, According To KBB

    September 7, 2026

    Magento StyleSmuggler zero

    September 7, 2026
    Facebook X (Twitter) Instagram
    Trending
    • See the New ‘Mystery Science Theater 3000’ Intro With a Theme by Jonathan Coulton [Exclusive]
    • 5 4-Door Sedans That Are Surprisingly Good In Snow, According To KBB
    • Magento StyleSmuggler zero
    • Working with your board around risk – why cyber responsibility can’t be shirked | Computer Weekly
    • Your Car’s New AI Assistant Is Very Friendly, Mostly Because It Wants Your Money
    • The Dark Ages’ Limited-Edition Atlan Statue: What You Need to Know
    • Grupo Financiero Inbursa Adopts Harvey Across Its Legal Organization
    • Matt Clifford Steps Down as ARIA Chair After Anthropic Move
    Facebook X (Twitter) Instagram Pinterest Vimeo
    AIToday7
    • Home
    • AI News
    • Tech News
    • AI Guides
    • Chatbots
    • Cybersecurity
    • Gadgets
    • More
      • Generative AI
      • Startups
    AIToday7
    Home»Uncategorized»Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities
    Uncategorized

    Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities

    aitoday7By aitoday7September 5, 2026No Comments2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe.

    The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as create privileged accounts.

    “Observed post-exploitation activity included delivery of Windows registry hive collection tools, Metasploit/Meterpreter-related Java payloads, and commands used to identify hosts, users, processes, and sensitive configuration data,” Arctic Wolf said.

    The cybersecurity company told The Hacker News

    The cybersecurity company told The Hacker News that the activity has targeted vulnerable PaperCut servers across the education sector, impacting organizations ranging from K-12 schools to major universities in the U.S. and Europe.

    Cybersecurity

    Some of the identified malicious activity includes –

    • Running discovery commands like uname, whoami, ver, and tasklist, and privileged account creation (“Administrator17”)
    • Inbound GET requests from “45.142.193[.]132” that request for “/custom/pcp_*.txt” and “/custom/web/pcp_*.txt” files on compromised hosts, containing harvested system and user data
    • Deliver credential-harvesting tools like lsa_collect.exe, lsa_collect_small.exe, and save_hives.exe via “certutil.exe” from “45.142.193[.]132”
    • Retrieve Meterpreter Java payloads from, and establish sessions to, “194.180.48[.]134”
    • Use “findstr” to search PaperCut *.config files for the terms “password,” “secret,” “ldap,” “bind,v and “token”

    Arctic Wolf said it also detected “lsa_collect.exe” in a sandbox that extracted specific registry keys to reconstruct the system BootKey, which can then grant the attacker access to the SAM database.

    “The concern is that those stolen logins could give attackers a pathway into other critical systems across the environment. Post-compromise activity included deployment of Windows registry,” Arctic Wolf said in a statement.

    Users are advised to restrict PaperCut servers

    Users are advised to restrict PaperCut servers from being exposed to the internet and monitor for the execution of cmd.exe, powershell.exe, or other scripting and command interpreters, along with commands containing whoami, tasklist, ver, or uname -a with pc-app.exe as the parent process.

    Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

    Post Views: 4

    attackers Exploit Flaws PaperCut Steal
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleBeaver County agency announces it was ransomware attack victim
    Next Article 8.9M Hit, $6.4M Fees
    aitoday7
    • Website

    Related Posts

    Cybersecurity

    Attackers conceal phishing lures using invisible Unicode characters

    September 6, 2026
    Uncategorized

    Seattle Times and Newsday are the latest publications to sue OpenAI and Microsoft

    September 5, 2026
    Uncategorized

    LockBit 5.0 Targets KALA Health in Ransomware Attack – DeXpose

    September 5, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    See the New ‘Mystery Science Theater 3000’ Intro With a Theme by Jonathan Coulton [Exclusive]

    September 7, 20260 Views

    5 4-Door Sedans That Are Surprisingly Good In Snow, According To KBB

    September 7, 20260 Views

    Magento StyleSmuggler zero

    September 7, 20260 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    Uncategorized

    Architecting memory and storage in the AI era

    aitoday7September 4, 2026
    Uncategorized

    Roland Releases Melody Flip, an AI Melody-Generation Plug-In for DAWs

    aitoday7September 4, 2026
    Uncategorized

    Home Depot Labor Day Sale (2026): BOGO on Best Grills and Tools

    aitoday7September 4, 2026

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    See the New ‘Mystery Science Theater 3000’ Intro With a Theme by Jonathan Coulton [Exclusive]

    September 7, 20260 Views

    5 4-Door Sedans That Are Surprisingly Good In Snow, According To KBB

    September 7, 20260 Views

    Magento StyleSmuggler zero

    September 7, 20260 Views
    Our Picks

    Architecting memory and storage in the AI era

    September 4, 2026

    Roland Releases Melody Flip, an AI Melody-Generation Plug-In for DAWs

    September 4, 2026

    Home Depot Labor Day Sale (2026): BOGO on Best Grills and Tools

    September 4, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Get In Touch
    • Disclaimer
    • Privacy Policy
    • Terms and Conditions
    © 2026 AIToday7. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.