Tech News
← Home  ·  All topics

Cve-2026-81578

3 GoKawiil briefs on this topic

AI-driven exploit campaign breaches 395 organizations via PaperCut flaws

GreyNoise reports that a likely Russian-speaking threat actor deployed hundreds of AI agents using OpenAI's Codex and DeepSeek models to build and launch exploits against two PaperCut NG/MF vulnerabilities. The campaign, which began August 31, compromised at least 440 servers across 395 organizations in 48 countries, mostly in education, with credentials stolen from 280 victims and admin access gained at 12 organizations.

Attackers exploit patched PaperCut flaws to steal data from print servers

Hackers are actively exploiting two recently disclosed PaperCut NG and MF vulnerabilities, CVE-2026-81578 and CVE-2026-82078, to bypass authentication and steal data from print management servers. PaperCut issued emergency fixes last week, but researchers at Defused say attackers are using the bypass to hijack the software's user-lookup function and dump database tables rather than pursue remote code execution as earlier reports suggested. Over 800 PaperCut servers remain exposed online according to Shadowserver, and PaperCut has not yet attributed the attacks or detailed post-compromise activity.

PaperCut issues second patch after first fix for exploited flaws was bypassed

PaperCut released a follow-up emergency update for PaperCut NG and MF after researchers found ways around its initial patch for actively exploited vulnerabilities. The company disclosed CVE-2026-82078, a critical unsafe dynamic class-loading bug, and CVE-2026-81578, a high-severity authentication bypass, which can be chained to let unauthenticated attackers execute code on vulnerable servers.