daily cyber × ai intelligence

index

tagged

[CVE-2026-82078]

6 editions · 5 items

September 11, 2026

  • GreyNoise traced the PaperCut NG/MF campaign (CVE-2026-81578, CVE-2026-82078) to 45.142.193.132, an IP it has watched since early July hitting Palo Alto, Ubiquiti, Citrix, SonicWall and Proxmox gear. Starting 31 August the actor built a lab with a vulnerable PaperCut server and an Active Directory box, built target lists via a Netlas.io API key, then ran hundreds of agents on an OpenAI Codex harness driving a DeepSeek model plus off-the-shelf offensive tooling. From empty workspace to RCE on a real victim took under four hours, first domain admin another two; once launched, 11 organizations fell in 26 seconds, and one US high school went from initial access to domain admin in seven minutes. PaperCut NG/MF runs as SYSTEM by default on Windows and is usually domain-joined (GreyNoise, BleepingComputer). Blackpoint Cyber reported the activity independently (The Hacker News). Attackers chaining the PaperCut pair for credential theft was earlier coverage; the AI orchestration and victim count are new. · Offensive AI in the Wild

in Four Hours to First Victim: AI Agents Ran a Global PaperCut Campaign

September 6, 2026

  • Attackers are chaining PaperCut authentication bypass and RCE flaws to steal credentials. Arctic Wolf observed CVE-2026-81578 and CVE-2026-82078 being used for command execution, reconnaissance and credential theft at schools and universities in the US and Europe. The Hacker News provides the new campaign-level detail following the earlier exploitation warning (earlier coverage). · Vulnerabilities & Exploits

in One Loophole, 100 Agents, 27 Minutes

September 1, 2026

Attackers Are Living in the Management Plane

JFrog Artifactory authentication bypass CVE-2026-82329 is actively exploited in the wild to mint admin tokens on build infrastructure, granting artifact-poisoning access to critical supply chains. A Metasploit module for PaperCut zero-days CVE-2026-81578 and CVE-2026-82078 is now public, narrowing the exposure window as roughly 1,000 instances remain vulnerable. Virtualizor VPS management platform was compromised via BGP hijack, affecting hundreds of hosting providers and their customer hypervisors and virtual servers. Anthropic is force-logging Claude users and removing payment data after commodity infostealers (Vidar, Lumma, StealC) harvested authenticated sessions for credential replay and usage fraud.

August 29, 2026

  • PaperCut NG/MF exploitation is live and the fixes are incomplete. The two flaws are now tracked as CVE-2026-81578 and CVE-2026-82078, and attackers are chaining them for unauthenticated code execution — the bug "gives an unauthenticated attacker remote control over PaperCut's trusted configuration, which could be used to execute arbitrary Java code inside the application" (The Hacker News). A second emergency patch has since shipped (BleepingComputer), and @watchtowrcyber, which is working with the vendor on the bypasses, tells users to "treat this as a trigger for incident response" and keep monitoring (earlier coverage). · Vulnerabilities & Exploits

in PaperCut Ships a Second Emergency Patch After Researchers Bypass the First