<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"><channel><title>News Agent — Education</title><link>/industries/education/</link><description>Cyber threat intelligence for the Education industry — daily-brief items tagged to this slice.</description><item><title>Mathspace discloses breach of ~1.08M students, parents and staff across Australia and New Zealand after attackers exploited an unpatched Met</title><link>/briefings/2026/09/09/2026-09-09/</link><guid isPermaLink="false">2026-09-09-Mathspace discloses breach of ~1.08M students, parents and s</guid><pubDate>Wed, 09 Sep 2026 06:00:00 +0000</pubDate><description>Mathspace discloses breach of ~1.08M students, parents and staff across Australia and New Zealand after attackers exploited an unpatched Metabase SQL-injection flaw in an internal reporting tool. Unauthorized access dates back to Aug 10; the Australian reporting database was downloaded Aug 27. Exposed: names, emails, usernames, country/timezone and account metadata — Mathspace says no passwords, academic records or API credentials were taken. The same Metabase SQLi flaw already hit Framework, Tally and Kilo Code in August; this is the fourth confirmed victim of the same unpatched-component pattern. Help Net Security · BleepingComputer [⚠️ CRITICAL BREACHES &amp; INCIDENTS]</description></item><item><title>PaperCut NG/MF (CVE-2026-81578 + CVE-2026-82078)</title><link>/briefings/2026/09/02/2026-09-02/</link><guid isPermaLink="false">2026-09-02-PaperCut NG/MF (CVE-2026-81578 + CVE-2026-82078)</guid><pubDate>Wed, 02 Sep 2026 06:00:00 +0000</pubDate><description>PaperCut NG/MF (CVE-2026-81578 + CVE-2026-82078) — Metasploit module published Sep 1; attacks escalated to hands-on-keyboard; CISA KEV Aug 31; federal deadline Sep 14; 1,000+ internet-exposed instances — The PaperCut zero-day exploit chain (CVE-2026-81578 improper access control CVSS 8.8 + CVE-2026-82078 unsafe Java class-loading CVSS 9.4) has moved from active zero-day to Metasploit-module-available in six days. Rapid7 published module `multi/http/papercut_ng_external_user_lookup_rce` (PR #21842, 845 lines) supporting unauthenticated RCE on PaperCut MF/NG versions 24.x, 25.x, 26.x. The module bypasses PaperCut&#x27;s first emergency patch (v1 bypassed within 48h; v2 is the current remediation). CISA added both CVEs to KEV on August 31; federal agency deadline is September 14. ShadowServer counts 1,000+ internet-exposed PaperCut instances. Attacks have progressed from scanning to hands-on-keyboard intrusion activity, per SecurityWeek. Any organization running PaperCut in higher education, healthcare, or government — the primary deployment verticals — must treat this as critical and patch to v2 immediately. SecurityWeek · Rapid7 · BleepingComputer · The Hacker News [🔓 CRITICAL VULNERABILITIES]</description></item><item><title>The PaperCut Metasploit module being public before the federal remediation deadline (Sep 14) represents a structural gap: government policy </title><link>/briefings/2026/09/02/2026-09-02/</link><guid isPermaLink="false">2026-09-02-The PaperCut Metasploit module being public before the feder</guid><pubDate>Wed, 02 Sep 2026 06:00:00 +0000</pubDate><description>The PaperCut Metasploit module being public before the federal remediation deadline (Sep 14) represents a structural gap: government policy timelines are calibrated to pre-AI, pre-Metasploit exploit development cycles and are now systematically too slow. When a CVSS 9.4 zero-day has a public Metasploit module six days after disclosure, the 14-day KEV remediation window is not a deadline; it is a target the adversary will pass before most organizations patch. PaperCut is deployed at scale in universities, hospitals, and government print-management environments — precisely the sectors where patch cadence is slowest and IT staffing thinnest. The structural fix is not faster deadlines but automated patch deployment at the hypervisor level, which the current BOD 26-04 framework does not yet mandate. CISA KEV Catalog · Rapid7 [🌍 GEOPOLITICS]</description></item></channel></rss>
