Security
PaperCut zero-days exploited to deploy AdaptixC2 implant on education print server
eSentire says attackers chained two PaperCut MF zero-days, a Java loader and a trojanized Copilot binary to reach a domain controller.
This edition was produced with artificial intelligence. Text and voice are generated automatically.
PaperCut MF zero-days exploited to deploy web shell and AdaptixC2 implant
eSentire’s Threat Response Unit detected exploitation of PaperCut MF zero-days CVE-2026-82078 and CVE-2026-81578 on August 31, 2026, against an Education-sector customer running version 24.0.2 on an internet-facing print server. Attackers used SQL injection to deliver an in-memory Java loader that deployed a web shell controlled via the X-Quad HTTP header, then pushed a trojanized Microsoft Copilot binary carrying an AdaptixC2 implant. They moved to a domain controller over the C$ share, dumped LSASS and SAM, enabled Restricted Admin mode, used pass-the-hash over RDP, and wrote NTDS.dit with ntdsutil. eSentire isolated the host and is monitoring the activity.
SEC Consult finds iCloud email spoofing flaws, Apple pays $15,000
Timo Longin of SEC Consult discovered two email spoofing vulnerabilities in Apple iCloud’s emailing infrastructure, both caused by parsing discrepancies between two internal SMTP parsers. The first abused bare carriage return characters in the From header to smuggle a second legitimate header past authentication. After Apple adapted one parser, a second method used dot-stuffing and dot-peeling to bypass From header checks again. The flaws let an authenticated user send mail appearing to come from any icloud.com address, including [email protected], passing SPF, DKIM and DMARC. Apple awarded a $15,000 bounty, confirmed fixes on 2025-11-12, and SEC Consult verified remediation on 2025-12-09.
From: [email protected] - Spoofing Arbitrary Apple iCloud Identities - SEC Consult →
Kevin Mandia’s Armadin raises $255.5M at $2.5B valuation
Armadin, the security startup founded by Mandiant creator Kevin Mandia, raised $255.5 million in a Series B round led by Andreessen Horowitz and Accel, valuing the company at more than $2.5 billion. Bain Capital Ventures, Redpoint, 8VC, Ballistic Ventures, Google Ventures, In-Q-Tel, Kleiner Perkins and Menlo Ventures also participated. The round comes six months after a $190 million Series A in March, bringing total funding above $445 million. Armadin runs always-on agentic swarms that chain vulnerabilities to hack into enterprises, replacing traditional penetration tests, aiming to help organizations find and seal holes before attackers can exploit them.
Microsoft report says attackers hold early AI advantage over defenders
Microsoft’s 2026 Digital Defense Report says cyberattackers are gaining from artificial intelligence faster than defenders, accelerating vulnerability discovery, malware development and post-compromise activity. AI cuts the time, expertise and cost needed to find and exploit weaknesses. Microsoft warns remediation is inherently slower than discovery, predicting a multi-year spike in known but unpatched vulnerabilities and stockpiling of zero-days. The median time between in-the-wild discovery and weaponization has fallen below 24 hours. Nation-state actors are already using AI: Chinese state-sponsored groups search for vulnerabilities, Russian actors use AI-generated tooling, and North Korean remote IT workers use it for personas and malware. Microsoft cautions most campaigns still retain human direction.
Microsoft says threat actors are ahead in the early AI race →
Amnesty documents Morocco’s Pegasus campaign against civil society
Amnesty International released a report titled We start with the verdict: Inside Morocco’s surveillance machine, documenting Pegasus spyware use against civil society from 2017 to 2021, with possible continued use afterward. Amnesty’s Security Lab cited technical and forensic evidence that the DGST acquired NSO Group’s Pegasus and targeted civil society from the start. Attack vectors ranged from one-click phishing links to zero-click exploits. The report traces earlier tools including Amesys Eagle, Hacking Team’s Remote Control System and Gamma Group’s FinSpy. A July OCCRP investigation with Forbidden Stories found new evidence of DGST spying. Morocco denied the findings, and pro-government outlets dismissed the reports.
Amnesty Report Documents Morocco’s Sustained Spyware Campaign Against Civil Society →