Hackers Turned a PaperCut Print Server Into a Path to the Domain Controller
Attackers chained two PaperCut MF zero-days to reach an education customer's domain controller in under two days.
eSentire reported that attackers exploited two PaperCut MF zero-days, CVE-2026-81578 and CVE-2026-82078, on an internet-facing version 24.0.2 server at an education customer. Unauthenticated Java execution led to an in-memory loader, a web shell, and an AdaptixC2 implant hidden in a modified Microsoft Copilot binary. Within two days the attackers stole a privileged service token, executed on a domain controller, dumped credentials, used an NTLM hash over RDP, and copied the Active Directory database. The flaws were described as actively exploited; eSentire isolated the host and advised patching and restricting access.