PaperCut Exploitation Escalates to Active Intrusions
CISA has added the vulnerabilities tracked as CVE-2026-82078 and CVE-2026-81578 to its KEV catalog. The post PaperCut Exploitation Escalates to Active Intrusions appeared first on SecurityWeek.
Threat actors are actively exploiting critical vulnerabilities in Langflow and Ruby on Rails to conduct credential-probing and command-and-control activities, with one flaw allowing arbitrary Python code execution with root privileges. The Langflow vulnerability (CVE-2026-0768, CVSS 9.8) stems from improper input validation, enabling remote code execution in a high-privilege context that attackers are leveraging in active campaigns.
PaperCut has issued emergency patches to address chained vulnerabilities that threat actors exploited in attacks targeting the company's print management software. The attacks primarily focused on higher education customers during 2023, highlighting the risk posed by coordinated vulnerability exploitation in widely-deployed enterprise software.
Threat actors exploiting PaperCut zero-day vulnerabilities are installing legitimate remote access tools on compromised internet-facing Application Servers to maintain persistent access. PaperCut Software disclosed the ongoing campaign and advised customers running NG and MF print management solutions to immediately restrict web access to trusted IP addresses only. The covert deployment of these tools demonstrates attackers' intent to establish long-term footholds on affected infrastructure.
Kaspersky told SecurityWeek that it patched the vulnerability affecting its Endpoint Security product. The post Nightmare Eclipse Drops ‘HardBreacher’ Kaspersky Product Exploit appeared first on SecurityWeek.