CVE-2019-11510, CVE-2026-81578, CVE-2026-82078
Domains:
qtproxy[.]xyz, qt-proxy[.]org, qt-team[.]com, fastlink[.]ws
Get tomorrow's brief in your inbox
Today: Two PaperCut zero-days (CVE-2026-81578, CVE-2026-82078) are under active exploitation against print management servers, with ~1,000 instances internet-exposed. Berlin is refusing to pay Rhysida ransomware's $2.3M demand after 5.7TB of government data was exfiltrated. ValleyRAT is hiding inside signed Chinese adware installers using DLL sideloading to bypass Defender.
PaperCut NG/MF Zero-Days Under Active Exploitation (CVE-2026-81578, CVE-2026-82078)
Two chained zero-days in PaperCut NG/MF print management software are being exploited by unauthenticated attackers to bypass authentication and achieve remote code execution. CVE-2026-81578 is a high-severity auth bypass allowing remote config modification. CVE-2026-82078 is a critical unsafe dynamic class loading flaw enabling arbitrary Java bytecode execution. EPSS scores are low (32nd/38th percentile), but active exploitation is confirmed. Huntress observed attacks against at least two customers starting August 26, focused on system discovery. WatchTowr found multiple patch bypasses requiring a second emergency patch. Roughly 1,000 instances are internet-exposed, mostly in North America and Europe. PaperCut has three prior CVEs in CISA KEV, two linked to ransomware.
Berlin Refuses $2.3M Rhysida Ransom After 5.7TB Government Data Theft
Rhysida ransomware group claimed responsibility for the attack on Berlin's Senate Department for Mobility, Transport, Climate Protection, and Environment. Data exfiltration occurred August 7-12; the breach was discovered August 14. Rhysida claims to have stolen 5.7TB including legal documents, financial records, HR files, plaintext credentials, IBANs, passport/ID data, payroll info, and personal data on 12,000+ individuals. The group demanded 30 BTC (~$2.3M). Berlin's governing mayor confirmed the city will not pay. Networks for two senate departments were shut down for containment.
ValleyRAT Backdoor Distributed via Signed Chinese Adware Installer
Kaspersky analyzed a ValleyRAT campaign where the backdoor masquerades as a legitimate Chinese desktop wallpaper tool (QN Wallpaper). The installer deploys signed adware binaries but replaces libcef.dll with a malicious version that performs DLL sideloading. The malicious DLL disables Windows Defender via the DisableAntiSpyware registry key, establishes persistence through file extension associations and startup folder drops, then delivers ValleyRAT. The advertising functionality is non-functional; it exists only as cover. The malware checks for admin group membership before proceeding.
c24e99f9437feacaa63766a3cde3fe3d. Monitor for DisableAntiSpyware registry modifications. Flag DLL sideloading from QNWallpaper paths (C:\Program Files\QNWallpaper\). Review endpoint policies that allow users to whitelist adware.Fake School Websites Target Education Sector at Record Volume
Check Point Research reports cybercriminals are creating thousands of education-themed phishing sites timed to the new academic year, targeting students, parents, and educators for personal and financial data theft. The education sector remains the most-targeted industry globally.
DoJ Corrects China Hacking Statement: U.S. Agencies Were Targets, Not Confirmed Victims
The DoJ revised its press statement about the QTFY (aka QT/QTCYBER) Chinese state-sponsored group, downgrading NASA, Federal Reserve, DoE, DoJ, HHS, NIH, and the U.S. Senate from "victims" to "targets." QTFY operates as a technical quartermaster for Chinese espionage, providing QScan (vuln scanning/exploitation) and QTRouter (obfuscation relay network) to multiple Chinese threat actors. The group works for Nanjing Xinjiuwei Network Technology Co, funded by the MSS. FBI seized domains for QScan and QTRouter. Lumen Black Lotus Labs found QTFY industrialized the creation of Operational Relay Box (ORB) networks using compromised IoT devices and leased VPSs, blending malicious traffic with legitimate activity via the "Fast Labyrinth" encrypted relay network.
qtproxy[.]xyz, qt-proxy[.]org, qt-team[.]com, fastlink[.]ws. Hunt for QTRouter/QScan indicators on network perimeters. Ensure Pulse Secure/Ivanti VPNs are patched against CVE-2019-11510 (EPSS 100th percentile, CISA KEV, ransomware-linked).Dutch Intelligence Agencies to Receive Expanded Surveillance Powers
The Netherlands proposed legislation granting AIVD and MIVD expanded powers including warrantless tapping for up to one year against foreign adversaries, streamlined approval for offensive hacking operations, and the ability to compel companies/citizens to provide data under criminal penalty. The bill introduces a "state emergency" provision suspending oversight obligations. Part of a broader European trend post-Ukraine invasion (Ireland, Germany, France pursuing similar expansions).
Former DIA IT Specialist Pleads Guilty to Espionage
Nathan Vilas Laatsch, 29, a former Defense Intelligence Agency IT specialist, pleaded guilty to attempting to pass secret and top-secret information to foreign spies. He was caught by an undercover FBI sting operation after a second transmission attempt.
VA White River Junction Data Breach
The U.S. Department of Veterans Affairs disclosed that unencrypted communications containing personal health information of veterans at the White River Junction, VT healthcare system were sent earlier this summer, resulting in an unintentional data exposure.
PaperCut NG/MF: CVE-2026-81578 and CVE-2026-82078
CVE-2026-81578 (High) is an authentication bypass allowing unauthenticated remote attackers to modify system configurations. CVE-2026-82078 (Critical) is an unsafe dynamic class loading vulnerability enabling arbitrary Java bytecode execution when system config parameters are manipulated. Emergency patches released for versions 24, 25, and 26. WatchTowr discovered additional patch bypasses, prompting a second emergency patch. Official release still in progress.
YARA-X 1.20.0 and YARA 4.5.6-4.5.8 Released
YARA-X 1.20.0 brings 14 improvements and 13 bugfixes, including a new --ignore-invalid-rules CLI option. YARA received three patch releases (4.5.6, 4.5.7, 4.5.8) with 32 total bugfixes.
The PaperCut exploitation continues a pattern of print management infrastructure being targeted by sophisticated actors, with three prior PaperCut CVEs already in CISA KEV. China's QTFY operation reveals the industrialization of relay networks using compromised IoT devices as proxy infrastructure, making attribution and detection significantly harder for defenders. The education sector phishing surge aligns with back-to-school timing, a recurring seasonal pattern that SMBs supporting schools should prepare for.