Threat Brief — 2026-09-05 — PaperCut Flaws Hit Education Sector
Active exploitation of PaperCut NG/MF vulnerabilities has shifted toward credential theft targeting U.S. and European schools and universities, according to new research from Arctic Wolf. Separately, fresh reporting on the Coder registry supply-chain compromise reveals the attack leveraged a Cloudflare compromise to turn a trusted distribution channel into an infostealer delivery mechanism. Two remaining findings — a pentesting methodology article and a Google weather-AI announcement — carry no actionable threat-intelligence value.
Top items
- PaperCut NG/MF exploitation now targeting education sector for credential theft — CVE-2026-81578KEV and CVE-2026-82078KEV, both already listed in CISA's Known Exploited Vulnerabilities catalog, are being actively exploited to steal credentials from schools and universities in the U.S. and Europe. Arctic Wolf's Adversary Research Team published new observations of in-the-wild attacks, marking the first specific sector-targeting detail for this campaign. This story was first reported 2026-08-27 by BleepingComputer. (src: The Hacker News)
- Coder registry compromise: Cloudflare vector identified — New technical reporting clarifies that the supply-chain attack against the Coder registry involved compromising Cloudflare infrastructure, which turned a trusted source into a delivery channel for infostealers. This provides additional detail on the initial-access vector behind the malicious Terraform module push first reported 2026-09-03 by BleepingComputer. (src: SecurityLab.ru)
Themes
Trusted-channel abuse persists. Both developing stories today — PaperCut's print-management software as a credential-theft pivot and the Coder registry's Cloudflare-compromised distribution path — illustrate attackers continuing to exploit infrastructure that organisations inherently trust. The PaperCut campaign demonstrates that KEV-listed vulnerabilities maintain momentum well beyond initial disclosure, while the Coder registry detail reinforces that CDN-level compromise can silently convert any trusted update pipeline into a malware channel.
