Zero-Days in PaperCut MF Chained to Compromise Active Directory in Education Sector
Analysts from eSentire have detailed a sophisticated intrusion that chained two zero-day vulnerabilities in PaperCut MF to reach the domain controller of an education-sector organization in less than two days.
The entry point was the card or badge query field. Attackers used it to deliver malicious Java code that enabled unauthenticated configuration changes and arbitrary bytecode execution on version 24.0.2 of the product. The flaws are tracked as CVE-2026-81578 and CVE-2026-82078.
The first-stage loader reassembled payload fragments directly in memory, started the next stage, and then deleted its own files. It was designed to operate across different versions of Tomcat. The subsequent web shell accepted commands through a custom HTTP header, read configuration data, and wiped its own log traces while sitting early in the request-processing pipeline, thereby blocking competing exploitation attempts by other groups.
The command-and-control implant was AdaptixC2, concealed inside a modified Microsoft Copilot binary downloaded from infrastructure hosted on Alibaba Cloud. After initial contact the implant remained silent for approximately 24 hours before operators resumed manual activity.
Privilege escalation required no password. The attackers located a domain-privileged service account running as an active process, copied its access token, and relaunched the implant with those elevated rights. On the domain controller the payload was delivered via administrative share and executed by temporarily altering the Windows PlugPlay service; the original service path was restored shortly afterward to reduce forensic evidence.
Once inside the domain controller the operators extracted credentials from memory and the registry, enabled Restricted Admin mode, used an NTLM hash to access systems via RDP, and copied the entire Active Directory database containing password hashes for all domain accounts.
Related articles
Six Months After tun0 Leak: Which Android VPN Clients Fixed Server Address Exposure and Which Ignored It
A detailed investigation reveals that Android VPN clients suffer from two distinct server address leaks when split tunneling is enabled. The first leak, tied to an unprotected local SOCKS proxy on 127.0.0.1, was quickly mitigated by most Xray and sing-box based clients through random ports and passwords. The second, more persistent leak allows excluded applications to bind sockets directly to the tun0 interface and discover the VPN server IP without root or special permissions. Only TeapodStream and OlConnect implemented owner-UID checks using ConnectivityManager.getConnectionOwnerUid, yet both initially mishandled the INVALID_UID response returned for excluded apps. AmneziaVPN has unmerged pull requests that correctly reject unknown owners, while sing-box offers a manual package_name_regex rule. v2rayNG closed the report as not planned, and major clients including WireGuard for Android, Mullvad, Proton VPN and others have issued no statements.
Part 2: How Third-Party Developers Closed the tun0 Leak in AmneziaVPN on Android
Third-party contributors to AmneziaVPN have detailed their fix for a VPN tunnel bypass affecting excluded applications on Android. The vulnerability allows any app, even those disallowed from the VPN, to bind sockets directly to the tun0 interface using SO_BINDTODEVICE and thereby discover the VPN server address. The team implemented a packet filter inside the client that queries Android via ConnectivityManager.getConnectionOwnerUid to determine packet ownership and drops traffic from unknown UIDs. The solution was integrated into both the Xray and AmneziaWG traffic paths, with the AmneziaWG hook placed inside amneziawg-go after packet parsing. Testing with leak_probe.py showed zero successful bypass attempts out of six methods when the filter was active, compared to six out of six without it. The developers submitted three pull requests and released a side-loaded test build, while noting remaining limitations such as raw sockets and tethering scenarios.
Cisco Confirms Active Exploitation of CVE-2026-76504 in Catalyst SD-WAN Manager
Cisco has confirmed that the critical vulnerability CVE-2026-76504 in Catalyst SD-WAN Manager has been exploited in attacks throughout September. The flaw carries a CVSS score of 9.8 and allows attackers to gain full administrator access without any credentials by bypassing API authentication through malformed URI encoding. The issue affects the login session handling mechanism, enabling forged requests to grant netadmin privileges by default. Similar URI manipulation techniques were observed earlier this month in Oracle PeopleSoft attacks. Patches are available across multiple release trains including 20.9.10.1, 20.12.8.2, 20.15.6.1, 20.18.4.1, 26.1.2.1 and 26.2.1, while older installations must migrate to supported versions. Cisco recommends restricting access to trusted hosts and placing the Manager behind firewalls until updates are applied. The vulnerability was discovered during routine support operations and verified by Cisco's Product Security Incident Response Team.
Apache WSS4J Library Addresses Seven Vulnerabilities Including Authentication Bypass Flaws
The Apache WSS4J library, used to apply WS-Security to SOAP messages in Java environments, has received updates fixing seven vulnerabilities. The development team disclosed multiple security advisories on September 30, 2026, covering the issues. Three vulnerabilities received an Important severity rating: CVE-2026-88920, CVE-2026-89238, and CVE-2026-95616. CVE-2026-88920 allows authentication bypass in the DOM security processor by injecting attacker-controlled keys into crafted unsigned sender-vouches SAML assertions. CVE-2026-89238 stems from improper handling of encryption headers, enabling attackers to force plaintext elements to be treated as decrypted headers and bypass security policies. The remaining four vulnerabilities were also resolved in the same coordinated update release.