hacker-news · Crawled Sep 5, 2026

Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities

5 IoCs
Read original article ↗

AI Summary

Threat actors are actively exploiting two vulnerabilities in PaperCut software, identified as CVE-2026-81578 and CVE-2026-82078, to conduct unauthorized access and credential theft targeting educational institutions in the U.S. and Europe. The attackers chain an authentication bypass with remote code execution to create privileged accounts, execute commands, and deploy credential-harvesting tools such as lsa_collect.exe and save_hives.exe. Post-exploitation activities include collecting Windows registry hives, searching configuration files for secrets, and exfiltrating data to attacker-controlled IP addresses.

AI-extracted · verify before operational use

Indicators of Compromise 5 extracted

Type Value Detail
IP 45[.]142[.]193[.]132 Details →
IP 194[.]180[.]48[.]134 Details →
Filename lsa_collect.exe Details →
Filename lsa_collect_small.exe Details →
Filename save_hives.exe Details →