Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
PaperCut Issues New Security Updates for Critical Flaws

PaperCut Issues New Security Updates for Critical Flaws

Posted on September 11, 2026 By CWS

On Thursday, PaperCut announced the release of a comprehensive security update to replace previous emergency patches that were addressing two actively exploited vulnerabilities. These updates pertain to versions 26.0.5, 25.0.13, and 24.1.10 of PaperCut NG/MF, which are now accessible for customer download.

Significance of the Latest Updates

According to PaperCut, the new maintenance releases have undergone thorough quality assurance testing and include all the security enhancements from prior emergency patches. Additionally, they feature further security reinforcements and have been subjected to the company’s standard release testing procedures.

These updates not only supersede the emergency patches but also address two regressions and implement enhanced measures against potential attack vectors. The vulnerabilities, identified as CVE-2026-81578 and CVE-2026-82078, have been actively exploited to bypass authentication and execute arbitrary code on vulnerable systems.

Exploitation by Cyber Threat Actors

Recent analyses by GreyNoise and Blackpoint Cyber reveal that a suspected Russian-speaking threat actor has been exploiting these vulnerabilities to breach approximately 395 organizations across 48 countries, with the majority located in the U.S. education sector.

The attacks employ a multitude of AI agents, utilizing OpenAI’s Codex and the DeepSeek model, to target organizations on a massive scale while deliberately avoiding entities in certain countries, including Russia and China. The malicious activities have been traced back to the IP address “45.142.193[.]132.”

Recommendations for PaperCut Users

GreyNoise has raised concerns about whether the threat actor’s primary aim is to develop access for other affiliated actors or to use the access for further objectives such as data theft or ransomware attacks.

Given the active exploitation of these vulnerabilities, PaperCut urges users to implement the latest security updates to ensure robust protection. Customers using an emergency patch build should transition to the new maintenance release promptly to safeguard their systems.

In conclusion, these updates are crucial for maintaining the security integrity of PaperCut systems amid ongoing exploitation attempts. Users are strongly encouraged to apply these fixes to mitigate risk and protect organizational data.

The Hacker News Tags:AI agents, Blackpoint Cyber, CVE-2026-81578, CVE-2026-82078, cyber attack, Cybersecurity, DeepSeek, GreyNoise, maintenance release, OpenAI Codex, PaperCut, security updates, Software Security, threat actor, Vulnerabilities

Post navigation

Previous Post: Microsoft Addresses Microsoft 365 Copilot Access Challenges
Next Post: Surfshark Security Breach: No User Data Compromised

Related Posts

Grinex Exchange Halts After .74M Cyber Heist Linked to Intelligence Grinex Exchange Halts After $13.74M Cyber Heist Linked to Intelligence The Hacker News
Exploitation of PAN-OS Security Flaw Intensifies Exploitation of PAN-OS Security Flaw Intensifies The Hacker News
⚡ Weekly Recap — SharePoint Breach, Spyware, IoT Hijacks, DPRK Fraud, Crypto Drains and More ⚡ Weekly Recap — SharePoint Breach, Spyware, IoT Hijacks, DPRK Fraud, Crypto Drains and More The Hacker News
Lumen Technologies Reinvents Exposure Management Strategy Lumen Technologies Reinvents Exposure Management Strategy The Hacker News
AI Assistants Exploited as Malware Command Channels AI Assistants Exploited as Malware Command Channels The Hacker News
67 Trojanized GitHub Repositories Found in Campaign Targeting Gamers and Developers 67 Trojanized GitHub Repositories Found in Campaign Targeting Gamers and Developers The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • GitLab Urges Immediate Updates to Address Critical Security Vulnerabilities
  • Surfshark Security Breach: No User Data Compromised
  • PaperCut Issues New Security Updates for Critical Flaws
  • Microsoft Addresses Microsoft 365 Copilot Access Challenges
  • Russian Hackers Exploit AI for Malware Evasion, Says Anthropic

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • GitLab Urges Immediate Updates to Address Critical Security Vulnerabilities
  • Surfshark Security Breach: No User Data Compromised
  • PaperCut Issues New Security Updates for Critical Flaws
  • Microsoft Addresses Microsoft 365 Copilot Access Challenges
  • Russian Hackers Exploit AI for Malware Evasion, Says Anthropic

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark