Ethical Hacking News
PaperCut has released a new security maintenance release that replaces all previously published emergency patches for two actively exploited security flaws. The move comes after a suspected Russian-speaking threat actor was found to be using the flaws to break into at least 395 organizations in 48 countries. The attacks used AI agents and OpenAI's Codex harness and a DeepSeek model to target organizations at scale, while avoiding entities in certain countries. The latest fixes are now available for download, and PaperCut customers are advised to apply them for optimal protection.
PaperCut has released a new security maintenance release to address actively exploited vulnerabilities. Two high-profile vulnerabilities (CVE-2026-81578 and CVE-2026-82078) have been found to be actively exploited, allowing attackers to bypass authentication and execute arbitrary code. A suspected Russian-speaking threat actor has been linked to the attacks, targeting 395 organizations in 48 countries, mostly in the US education sector. The attacks used AI agents and OpenAI's Codex harness to target organizations at scale, avoiding certain countries. PaperCut customers running emergency patch builds are advised to move to the new maintenance release for optimal protection. The new release contains all previously published emergency patches and additional security hardening. Organizations must prioritize their cybersecurity posture and stay informed about emerging threats to prevent exploitation of vulnerabilities.
The threat landscape has taken a severe turn in recent days, with a number of high-profile vulnerabilities being actively exploited by malicious actors. In a bid to address these threats, PaperCut has released a new security maintenance release that replaces all previously published emergency patches. This move comes after two security flaws were discovered that have been causing significant issues for organizations around the world.
The two vulnerabilities, CVE-2026-81578 and CVE-2026-82078, have been found to be actively exploited in the wild, allowing attackers to bypass authentication and execute arbitrary code on susceptible instances. The attacks have been particularly aggressive, with a suspected Russian-speaking threat actor using the flaws to break into at least 395 organizations in 48 countries, mostly concentrated in the US education sector.
The attacks used a combination of AI agents and OpenAI's Codex harness and a DeepSeek model to target organizations at scale, while avoiding entities in Russia, China, Hong Kong, Thailand, Iran, and 23 other countries. The activity originates from the IP address "45.142.193[.]132." The attacker's goal is unclear, but it is believed that they may be seeking to gain access to sensitive information or deploy ransomware.
In light of the active exploitation efforts, it is essential that users apply the latest fixes for optimal protection. PaperCut customers running an emergency patch build are advised to move to a maintenance release. The new security maintenance release contains all of the security fixes issued in Emergency Patch Releases 1, 2, and 3, plus additional security hardening.
The release has undergone complete QA testing and has been deemed safe for customers to download. The vulnerabilities have been a significant concern for organizations, and the swift action by PaperCut to address them is a welcome move. The company's commitment to security is clear, and their efforts to provide timely patches and fixes are essential in protecting organizations from the ever-evolving threat landscape.
The incident highlights the need for organizations to stay vigilant and proactive in their approach to cybersecurity. Regular patching and updates are crucial in preventing exploitation of vulnerabilities, and the importance of staying informed about emerging threats cannot be overstated. As the threat landscape continues to evolve, it is essential that organizations prioritize their cybersecurity posture and take proactive steps to protect themselves from the ever-present threat of cyber attacks.
In conclusion, the release of the new security maintenance release by PaperCut is a significant development in the ongoing battle against cyber threats. The swift action taken by the company to address the actively exploited vulnerabilities is a testament to their commitment to security, and their efforts to provide timely patches and fixes are essential in protecting organizations from the ever-evolving threat landscape.
Related Information:
https://www.ethicalhackingnews.com/articles/PaperCut-Replaces-Emergency-Patches-with-Fixes-for-Two-Actively-Exploited-Flaws-Amid-Widespread-Cyber-Attacks-ehn.shtml
https://thehackernews.com/2026/09/papercut-replaces-emergency-patches.html
https://nvd.nist.gov/vuln/detail/CVE-2026-81578
https://www.cvedetails.com/cve/CVE-2026-81578/
https://nvd.nist.gov/vuln/detail/CVE-2026-82078
https://www.cvedetails.com/cve/CVE-2026-82078/
Published: Fri Sep 11 03:24:28 2026 by llama3.2 3B Q4_K_M