Skip to content
feed: live
>_0dayNews
threat intel
● Breaking

PaperCut Attackers Steal Credentials From Schools

Arctic Wolf finds PaperCut exploitation now targeting US and European schools with credential theft as the post-exploitation objective.

PaperCut Attackers Steal Credentials From Schools
Image: AI-generated — no human photographer / 0dayNews AI Cover · Generated on-site infrastructure — no external license
kilobaudDave "Kilobaud" Ferris·Published ·1 min read

Arctic Wolf’s Adversary Research Team has documented a wave of PaperCut exploitation specifically targeting schools and universities in the United States and Europe, The Hacker News reported Friday. The post-exploitation focus is credential theft.

The CVEs are the same two that landed on CISA’s Known Exploited Vulnerabilities catalog last week. CVE-2026-81578 is the authentication bypass (CVSS 9.8, critical), and CVE-2026-82078 is the remote code execution flaw that follows from it (CVSS 9.1, critical). What Arctic Wolf’s findings add is a clearer picture of what attackers are doing once inside.

Education is a consistent target for credential theft operations. Schools and universities hold large volumes of personally identifiable information, often run lean security operations, and deploy print management infrastructure that reaches broadly across internal networks. A PaperCut server with wide internal visibility becomes a useful position for lateral movement and credential harvesting after the initial authentication bypass.

The credential theft focus matters beyond the immediate institutions. Education sector breaches tend to feed downstream fraud: financial aid applications, student loan accounts, tax filings, employment verifications. Credentials harvested in bulk from a sector that processes millions of students rarely stay contained to one use case.

CISA’s federal patch deadline for both CVEs is September 14. For any organization running unpatched PaperCut NG or MF, the Arctic Wolf findings make the case that September 14 is a practical floor, not a ceiling. Authentication bypass alone is enough to provide initial access; the RCE makes persistent credential harvesting a scripted operation.

The pattern of targeting print management infrastructure for post-exploitation actions is not new. Earlier this year, credential theft campaigns similarly leveraged vulnerabilities in Langflow to reach AI development credentials stored in cloud environments. The vectors differ; the operational logic is the same.

What to do

Apply PaperCut’s Emergency Patch Release 2, which addresses both CVEs. Education-sector organizations should assume that any PaperCut server accessible to the internal network may have already been accessed and prioritize reviewing authentication logs for anomalies. Rotate credentials that passed through or were stored on PaperCut-connected systems before patching. CISA’s KEV entry includes mitigation steps for environments that cannot patch immediately.

Related CVEs

Found this useful? Share it.