Attackers are actively exploiting two critical vulnerabilities in PaperCut software to steal credentials from educational institutions across the United States and Europe. Arctic Wolf's Adversary Research Team documented the campaign, which leverages CVE-2024-81578 and CVE-2024-82078 to breach schools and universities.

The two flaws form a dangerous chain. CVE-2024-81578 bypasses authentication mechanisms, allowing attackers to access restricted functions without valid credentials. CVE-2024-82078 enables remote code execution once authentication is bypassed. Together, they create a pathway for attackers to execute arbitrary commands on compromised systems.

PaperCut develops print management software used by thousands of organizations globally, including educational institutions. The software manages document workflows, billing, and user access controls in campus printing environments. Schools and universities rely on PaperCut for infrastructure spanning student labs, administrative offices, and library systems. This widespread deployment makes the software an attractive target.

Arctic Wolf researchers observed attackers using the vulnerability chain for command execution and reconnaissance activities. After gaining initial access, threat actors enumerate systems, identify active user accounts, and establish persistence mechanisms. The ultimate objective centers on credential harvesting. Stolen credentials grant attackers access to broader campus networks, allowing them to move laterally across systems containing sensitive data about students, faculty, and research operations.

The education sector faces particular risk from this campaign. Universities store personally identifiable information on millions of students, including social security numbers, financial records, and biographical data. Research institutions maintain intellectual property and grant funding details. Attackers can monetize stolen credentials through sale on dark web marketplaces or deploy them in follow-on attacks against connected organizations.

PaperCut addressed these vulnerabilities with patches released recently. The company designated both flaws as critical with CVSS scores reflecting severe impact. However, adoption of patches in educational environments typically lags behind private sector organizations. Budget constraints, competing IT priorities, and complex deployment architectures slow patching cycles at many schools and universities.

The geographic focus on U.S. and European institutions suggests either targeted campaigns by nation-state actors or opportunistic exploitation by cybercriminal groups seeking high-value targets. Educational networks often maintain looser security perimeters than financial or government sectors, making them attractive to less sophisticated threat actors. Conversely, the coordinated nature and technical sophistication documented by Arctic Wolf hints at organized operations.

Organizations running PaperCut should apply available security patches immediately. Administrators should verify systems are updated to the latest versions. Network segmentation can limit lateral movement if PaperCut systems become compromised. Monitoring for suspicious authentication attempts and command execution on PaperCut servers helps detect active exploitation.

Schools and universities should prioritize credential rotation across systems potentially accessed by compromised PaperCut instances. Multi-factor authentication deployment strengthens defenses against stolen credential attacks. Incident response teams should prepare for possible breaches and establish communication protocols with affected students and staff if data theft occurs.

This campaign underscores how infrastructure software vulnerabilities propagate risk across entire sectors. Educational networks interconnecting thousands of users create attack surfaces that threat actors exploit methodically. Timely patching and defensive monitoring remain essential controls against this emerging threat.