Threat Brief — 2026-09-01 — PaperCut hits KEV, Exchange exposure persists
Executive summary: Two PaperCut NG/MF zero-days now appear in CISA's Known Exploited Vulnerabilities catalog, confirming active in-the-wild exploitation and raising the urgency for any exposed print-management servers. Nearly 22,000 unpatched Microsoft Exchange servers remain internet-exposed to a high-severity mailbox-hijack authentication bypass. Iranian actor Nimbus Manticore has expanded its recruiter-lure toolkit with cross-platform RATs targeting Linux and macOS, broadening the traditional Windows-only footprint of these campaigns.
Top items
- CISA adds two PaperCut NG/MF CVEs to Known Exploited Vulnerabilities catalog. CVE-2026-81578KEV (missing authentication for a critical function) and CVE-2026-82078KEV (unsafe reflection allowing arbitrary Java bytecode execution) are both now listed as exploited in the wild. This continues a story first reported on 2026-08-27 by BleepingComputer; the KEV addition marks escalation from initial exploitation disclosure to confirmed active threat requiring federal-agency remediation timelines. (src: CISA KEV)
- ~22,000 Microsoft Exchange servers remain unpatched against high-severity mailbox-hijack vulnerability. Internet-exposed Exchange instances are vulnerable to an authentication bypass that allows an attacker to take over all user mailboxes on a server. The scale of exposure—nearly 22,000 servers—suggests many organisations have not yet applied the relevant patch, making this an attractive target for credential and data theft. (src: BleepingComputer)
- Iranian Nimbus Manticore deploys new cross-platform RATs via fake recruiter coding tests. Two previously undocumented malware families have been attributed to this group, extending its reach beyond Windows to Linux and macOS. The campaign uses legitimate-looking coding challenges as delivery vectors, continuing a well-established Iranian TTP but with a materially expanded platform footprint. (src: The Hacker News)
- "HardBreacher" PoC exploit published for Kaspersky Endpoint Security privilege-escalation flaw. Researcher Nightmare Eclipse (also known as Chaotic Eclipse) released a proof-of-concept exploit targeting a local privilege-escalation vulnerability in Kaspersky Endpoint Security. Kaspersky has acknowledged the disclosure. This develops a story first reported on 2026-08-31 by SecurityLab; the new element is a named, packaged PoC ("HardBreacher") being publicly released, increasing the likelihood of adoption by less sophisticated actors. (src: Xakep)
- Social-engineering trend: attackers favour repeatable, low-sophistication entry techniques. Analysis highlights the continued prevalence of clipboard-hijacking via fake CAPTCHA pages—a visitor is instructed to "prove they are human," a command is silently placed on their clipboard, and they are talked through pasting it into a terminal. The appeal is repeatability and scale rather than technical sophistication, which aligns with the broader pattern of "ClickFix"-style social engineering observed across multiple recent campaigns. (src: The Hacker News)
Themes
KeV momentum on print and document infrastructure. The PaperCut KEV listings, following earlier exploitation reports, place print-management servers squarely in the active-attacker category alongside the Exchange exposure. Both product families are common in enterprise environments but often run with less patching discipline than core IT systems, making them pivot points for initial access.
Cross-platform expansion of established actors. Nimbus Manticore's move to Linux and macOS RATs reflects a broader industry trend where threat groups historically focused on Windows are building or acquiring multi-platform tooling, reducing the protective value of OS monocultures in targeted environments.
Social engineering as the reliable initial-access workhorse. The clipboard-hijacking CAPTCHA technique, the recruiter-lure coding tests, and the tech-support vishing campaigns all rely on human interaction rather than software exploitation—reinforcing that "asking" remains the most common and repeatable way into an organisation.
