Webinar

September 2026 TRU Intelligence Briefing On-Demand

Watch eSentire’s Threat Response Unit (TRU) as they share new research-driven observations of malware, notable vulnerabilities, threat actor groups, and cyber activity affecting the threat landscape.

During the September Threat Intelligence Briefing, TRU reviewed:

ThreatScape: In this section, TRU will provide a brief update on recent geopolitical cyber activity, and TRU will cover recent vulnerabilities CVE-2026-82078 / CVE-2026-81578 (PaperCut), CVE-2026-18577 (N-Central) and CVE-2026-68820 (Windows EoP exploit leveraged by DPRK operatives in Operation Dream Job campaign). TRU will also cover recently observed threats DeviceManagerRAT, TWINLOOT and TuoniC2.

Cruciferra - Malware Loader & EDR Killer: The TRU team will cover Cruciferra MaaS. Cruciferra is a Malware-as-a-Service loader advertised on underground hacking forums since November 2025. Its promoted capabilities include AV/EDR termination via Bring Your Own Vulnerable Drivers (BYOVDs) and Windows SmartScreen bypass through DLL side-loading.

PaperCut MF/NG Zero-Day Exploit Chain (CVE-2026-81578 + CVE-2026-82078): TRU will cover the actively exploited PaperCut zero-days disclosed on August 27, 2026, affecting PaperCut NG and PaperCut MF print management products. By chaining an authentication bypass (CVE-2026-81578) with an unsafe class-loading flaw (CVE-2026-82078), an unauthenticated attacker can achieve full RCE. In addition to a discussion of the vulnerability, TRU will dive into remediation and mitigation recommendations that organizations can employ to help harden public-facing infrastructure.

This webinar also included a live Q&A.

Watch the Webinar

Watch eSentire’s Threat Response Unit (TRU) as they share new research-driven observations of malware, notable vulnerabilities, threat actor groups, and cyber activity affecting the threat landscape.

During the September Threat Intelligence Briefing, TRU reviewed:

ThreatScape: In this section, TRU will provide a brief update on recent geopolitical cyber activity, and TRU will cover recent vulnerabilities CVE-2026-82078 / CVE-2026-81578 (PaperCut), CVE-2026-18577 (N-Central) and CVE-2026-68820 (Windows EoP exploit leveraged by DPRK operatives in Operation Dream Job campaign). TRU will also cover recently observed threats DeviceManagerRAT, TWINLOOT and TuoniC2.

Cruciferra - Malware Loader & EDR Killer: The TRU team will cover Cruciferra MaaS. Cruciferra is a Malware-as-a-Service loader advertised on underground hacking forums since November 2025. Its promoted capabilities include AV/EDR termination via Bring Your Own Vulnerable Drivers (BYOVDs) and Windows SmartScreen bypass through DLL side-loading.

PaperCut MF/NG Zero-Day Exploit Chain (CVE-2026-81578 + CVE-2026-82078): TRU will cover the actively exploited PaperCut zero-days disclosed on August 27, 2026, affecting PaperCut NG and PaperCut MF print management products. By chaining an authentication bypass (CVE-2026-81578) with an unsafe class-loading flaw (CVE-2026-82078), an unauthenticated attacker can achieve full RCE. In addition to a discussion of the vulnerability, TRU will dive into remediation and mitigation recommendations that organizations can employ to help harden public-facing infrastructure.

This webinar also included a live Q&A.

Get The Webinar