Ethical Hacking News
PaperCut Flaws Exploited in Attacks on U.S. and European Schools: A Threat to Education Sector Security
A new wave of cyber attacks has targeted schools and other education organizations in the U.S. and Europe, exploiting vulnerabilities in the PaperCut software to gain access to sensitive credentials and systems. The attackers used two recently disclosed PaperCut flaws to chain an authentication bypass with remote code execution, putting sensitive information and systems at risk. Defenders are advised to review PaperCut server.log files, monitor pc-app.exe, and install security fixes to prevent such attacks from occurring in the future. Stay informed about the latest security vulnerabilities and take proactive measures to protect sensitive information and systems.
The education sector has been hit by a new wave of cyber attacks using vulnerabilities in the PaperCut software.Attackers exploited two recently disclosed PaperCut flaws to gain access to sensitive credentials and systems.The attackers used Meterpreter Java payloads and credential-harvesting tools to establish remote sessions and collect system and user data.Defenders are advised to review server.log files and monitor pc-app.exe for command shells to detect potential attacks.Keeping PaperCut management interfaces off the public internet and installing security fixes are crucial measures to protect against such attacks.The recent attack highlights the need for increased vigilance and proactive measures to prevent future attacks.
The education sector has been hit by a new wave of cyber attacks, with attackers exploiting vulnerabilities in the PaperCut software to gain access to sensitive credentials and systems. The attacks, which have targeted schools and other education organizations in the U.S. and Europe, demonstrate the rapid pace at which newly disclosed vulnerabilities can be turned into real-world attacks, putting sensitive information and systems at risk.
According to Arctic Wolf researchers, the attackers used two recently disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, to chain an authentication bypass with remote code execution to run commands, perform reconnaissance, and create privileged accounts. The attack vector involved the use of Meterpreter Java payloads to establish remote sessions, as well as the downloading of credential-harvesting tools with certutil.
The attackers also searched PaperCut configuration files for passwords, secrets, LDAP settings, and tokens, and used the lsa_collect.exe tool to extract registry keys to recover the Windows BootKey, which could give attackers access to the SAM database and stored credentials. In addition, the attackers created a privileged account named Administrator17, and collected system and user data.
This latest attack highlights the importance of staying up-to-date with the latest security patches and updates, particularly in the education sector, where sensitive information and systems are often at risk. Defenders are advised to review PaperCut server.log files for known exploitation indicators and look for unusual files, as well as monitor pc-app.exe for command shells and investigate commands like whoami, tasklist, ver, and uname.
Furthermore, defenders should also keep PaperCut management interfaces off the public internet and install the vendor's security fixes, as well as be cautious of credential-harvesting tools, unexpected privileged accounts, and suspicious requests to custom/pcp_*.txt. The use of secure protocols and encryption is also crucial in protecting against such attacks.
The PaperCut software has a history of being exploited, including attacks that delivered LockBit ransomware. The recent attack highlights the need for increased vigilance and proactive measures to prevent such attacks from occurring in the future.
In conclusion, the recent attack on the education sector using PaperCut flaws highlights the importance of staying informed about the latest security vulnerabilities and taking proactive measures to protect sensitive information and systems. Defenders must remain vigilant and take immediate action to patch vulnerabilities, update software, and implement robust security measures to prevent such attacks from occurring in the future.
Related Information:
https://www.ethicalhackingnews.com/articles/PaperCut-Flaws-Exploited-in-Attacks-on-US-and-European-Schools-A-Threat-to-Education-Sector-Security-ehn.shtml
https://securityaffairs.com/198476/hacking/papercut-flaws-exploited-in-attacks-on-u-s-and-european-schools.html
https://thehackernews.com/2026/09/attackers-exploit-papercut-flaws-to.html
https://nvd.nist.gov/vuln/detail/CVE-2026-81578
https://www.cvedetails.com/cve/CVE-2026-81578/
https://nvd.nist.gov/vuln/detail/CVE-2026-82078
https://www.cvedetails.com/cve/CVE-2026-82078/
https://malwaretips.com/blogs/lockbit-5-0-ransomware/
https://any.run/malware-trends/lockbit/
Published: Sat Sep 5 15:21:06 2026 by llama3.2 3B Q4_K_M